SourceForge accepts OpenID logins in 2008
In spring 2008 SourceForge, then the best-known home of open source projects, began accepting OpenID logins. What that meant for developers and the standard.
HistoryPublished
In early May 2008 SourceForge.net, at that time the best-known hosting place for open source projects, announced that visitors could log in with an OpenID. The archived European OpenID blog reported it on 4 May 2008 with enthusiasm. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to SourceForge, to the OpenID Foundation or to the former OpenID Europe Foundation.
What happened
SourceForge was a central platform for open source software. Developers used it to host code, track bugs, publish downloads and run mailing lists, and almost everyone who contributed to free software had an account there. In spring 2008 the operators added OpenID login. A user with an OpenID from any provider could sign in with it rather than creating a SourceForge password.
The blog post made one technical point clearly. SourceForge was not an OpenID provider. It did not hand out identities. It was a relying party: it accepted identities issued elsewhere. That role is explained in What is a relying party?. The post treated this as the healthier of the two roles for the standard’s health, as it spreads the acceptance of OpenID without making one company the owner of everyone’s identity. It also pointed to a smaller bookmarking service that had stopped offering ordinary registration altogether and accepted only OpenID.
What SourceForge said
The announcement from SourceForge, quoted in the blog post, described OpenID as getting “tremendous traction”. The team said it was happy to join, and that, as a decentralised open source standard, OpenID was “a perfect fit”. They hoped it would make user interaction and participation easier across the whole open source community. The post also linked to a developer who pointed out that SourceForge was now one of the most prominent single sites accepting OpenID, and who explained what advanced options existed for people who wanted to use their SourceForge profile page as their own OpenID.
Why developers were the right audience
OpenID had started inside the blogging world and spread first to technical communities. Open source developers fit the idea well: they were comfortable with URLs as identifiers, they cared about avoiding lock-in to one company, and they already maintained personal sites or profile pages that could serve as an identifier. A large developer site accepting OpenID gave the technology credibility beyond blog comments.
It also sits in a wave of developer-facing adopters. In October 2008, Q&A and community sites were among the first relying parties for new providers; the Google and Windows Live ID story lists several. The pattern was the same: sites for technical audiences first, mass-market sites later and only with large providers behind them.
What users actually saw
The announcement describes the feature rather than the screen, but the standard OpenID flow gives the idea: a user enters an OpenID, is sent to the provider, confirms the sign-in there and comes back to SourceForge logged in, with no new SourceForge password to remember. That sounds unspectacular, but for developers who kept separate accounts on many project pages, forums and tools it was a visible benefit. Because the post describes only the login, we do not know how many accounts were actually linked to an OpenID.
The limits of the relying-party route
A site that accepts OpenID gets a verified identifier, but only if users have one and know how to use it. In 2008 most people did not. A relying party therefore usually kept its password login alongside OpenID, so OpenID rarely replaced anything; it was an extra door. Large providers such as Yahoo improved the odds by turning millions of existing accounts into usable OpenIDs, but the sign-in buttons of the large platforms eventually crowded out the generic OpenID option. Reasons for the decline are collected in Why OpenID 2.0 faded.
What is the situation today?
OpenID 2.0, the protocol SourceForge used, has been retired by most large providers, and reference works mention that Stack Overflow ended OpenID support in March 2018 because few people used it. We have not checked whether SourceForge still supports OpenID today and do not claim that it does. Sites that want a single login for many services now typically use single sign-on built on OpenID Connect, or passkeys. The OpenID timeline shows where this episode sits in the larger story.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.