openideurope.eu

Five lessons from OpenID for the EU Digital Identity Wallet

What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.

HistoryPublished

OpenID 2.0 was not a bad idea. It was a good idea that met five ordinary problems and lost to them. The EU Digital Identity Wallet is a much better resourced project, with law behind it, but the same five problems are waiting. Here they are, one by one, with what each means for the wallet.

1. Usability beats elegance

What happened. OpenID asked users to type a web address as their login or to pick from a row of logos. Developers admired the design, and ordinary people could not explain it. Facebook’s single button won with one click. See Facebook Connect vs OpenID.

What it means for the wallet. Sharing a credential must feel at least as easy as paying with a phone. That means few steps, plain language about what is being asked, and a recovery path when the phone is lost. A wallet that is secure but fiddly will be used only when a rule forces it.

2. Both sides of the market must show up

What happened. Many companies issued OpenIDs, few websites accepted them, and users had no reason to use an OpenID that few sites took. The classic chicken-and-egg problem hurt it for years, as Why OpenID 2.0 faded explains.

What it means for the wallet. The EU answers with law. Member states must offer a wallet by about the end of 2026, and banks and very large platforms must accept it from about a year later. That is a strong push, but acceptance by a service is not the same as being the easy option at the login screen. If a site buries the wallet button, people will not find it. Acceptance by relying parties of every size is the metric to watch, and small businesses are largely exempt from the duty.

3. Phishing must be designed out, not warned about

What happened. A login that begins on a website and continues on a provider’s page can be imitated. OpenID 2.0 gave users no way to check the provider page, and warnings about fake pages did little. Real defences came later, in the form of origin-bound credentials such as passkeys and hardware keys.

What it means for the wallet. A malicious website can ask for far more than a password, such as a passport copy or a date of birth. The wallet design addresses this by registering services that ask for data, and the wallet can show who is asking. The protection holds only if registration is enforced and if users can read the request. Our page on wallet security goes through the model.

4. A login is not an identity

What happened. OpenID proved that you controlled an account. It said nothing about who you were. When Romania’s government looked at OpenID in 2008, it noted that the technique was not accurate enough for verifying users and wanted mobile operators and companies to act as a buffer. That episode is in OpenID in government.

What it means for the wallet. The wallet’s credentials are issued by authorities and organisations that checked the person, and the EU defines levels of assurance for them. This is the single largest advantage over OpenID. It also creates a duty: services should ask for the attribute they need, such as ‘over 18’, not a full ID.

5. Whoever sits in the middle sees everything

What happened. In OpenID and its successor OpenID Connect, the provider takes part in every login and can see which sites you use. As a handful of providers took most of the market, concentration followed. Social login made that visible when Facebook and Google became the preferred buttons.

What it means for the wallet. The wallet’s design avoids a central provider in each transaction. The issuer is not contacted when you present a credential. Whether that gives real privacy depends on the details, including how credentials are linked across uses, a subject covered in wallet privacy. Another form of concentration remains: if most people use one national wallet app, its maker and the platform it runs on become gatekeepers.

Why the history is worth knowing

It is tempting to treat OpenID as a failed experiment and the wallet as a clean start. The record suggests otherwise. Many of the people and companies that shaped OpenID, and many of its ideas, carried over into OpenID Connect, into the OpenID4VC protocols and into the thinking behind the wallet. What failed was not the aim but the conditions around it. Knowing which conditions were missing, a reason to accept, a trustworthy issuer and a safe interface, is the best way to judge whether the wallet will do better.

What you can do

You do not have to wait for the perfect system.

  • Keep a second way in. The EU law says the wallet must not be a precondition for services. Keep passkeys and a password manager for the accounts you cannot afford to lose.
  • Look at what is asked. If a service wants more than it should, say so and, where possible, decline.
  • Treat the wallet as one tool. It proves facts about you to services. It does not replace good habits for email and recovery.

The takeaway

OpenID’s founders tried to build a world where people controlled their identity. The tools were not ready and the incentives were not aligned. The EU wallet changes the incentives with a law and with state-issued credentials. What remains is the oldest lesson in the story: people use the system that is easiest. For the road from one to the other, read From OpenID to the EU wallet, and for the dates, the OpenID timeline. The basics of the wallet are in The EU Digital Identity Wallet.

An editorial assessment based on the history documented on this site and the wallet rules as of October 2026.

More in History