Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
HistoryPublished
In 2008 a small Swiss company tried something that most OpenID providers did not: it made the login strong. Clavid AG ran an OpenID identity provider in Switzerland and spent that year plugging stronger authentication methods into it. The old OpenID Europe blog followed each step.
The first Swiss identity provider
The OpenID Europe blog reported on 28 March 2008 that Clavid had launched a restricted area offering OpenID authentication based on smart-card tokens issued by Swiss Post, alongside ordinary username and password. A later press release said the company had been operating the first Internet identity provider in Switzerland since November 2007. The same release describes Clavid as a provider of IT security solutions working with SAML as well as OpenID. The company did not want to invent new authentication; it wanted to take existing mechanisms and make them available through OpenID and SAML. (SAML is explained in identity federation.)
The Swiss OpenID association, which called itself a local chapter of the OpenID Europe Foundation, was described at the time as still in its start-up phase. The wider structure is covered in the European OpenID community.
Four ways to be stronger than a password
Over the rest of 2008 the blog recorded four additions.
Biometric InternetPassport (August 2008). The AXSionics InternetPassport, built by a Swiss company, provided two- and three-factor authentication with the user’s fingerprint. According to the announcement it needed no special drivers or readers: the card showed a visual code, and the user’s fingerprint on the card produced the response code. Clavid integrated it so that fingerprints could be used on any OpenID-enabled site.
YubiKey (August 2008). A password plus a one-time code from a YubiKey, covered in detail in OpenID meets the YubiKey.
Client certificates (November 2008). Users could add existing SSL/TLS client certificates, whether from an employer, a government or self-signed, to their account, and combine several certificates in one OpenID. The idea was free choice of the issuer.
Press release with AXSionics (December 2008). AXSionics announced that the combination of InternetPassport and OpenID, in test since August, was now available to everyone free of charge through Clavid. The company described itself as a 2003 spin-off from a Swiss university of applied sciences in Biel/Bienne, and said biometric data stays on the card under the user’s control. Treat the awards and funding figures in that press release as the company’s own claims.
An additional item from October 2008 is a report on OpenID written by a Clavid representative for DIGMA, a Swiss journal for data law and information security. It was published in German.
Why it mattered
OpenID 2.0 only moved the login to another place. If the provider’s login was a weak password, the whole chain was weak. Clavid’s approach decoupled the two: the protocol stayed the same, while the credential behind it could be a card, a key, a fingerprint or a certificate. That is close to the idea behind today’s phishing-resistant multi-factor authentication and to what the European standards call levels of assurance.
The attempt also showed the problem OpenID never solved. Strong credentials need hardware, setup and a reason to care, and ordinary websites did not accept OpenID widely enough for users to see the benefit. See why OpenID 2.0 faded.
What became of Clavid
We could not find a public notice of closure, an acquisition or a successor service. In October 2026 the web addresses that the company used in 2008 no longer resolved when we tried them. The honest answer is therefore open: the service appears to be gone, but the reason and date are not documented in sources we could verify. If you have a reliable source, please tell the editorial team.
Today in Switzerland
Switzerland is moving to a state-issued electronic identity, the E-ID, which Swiss voters approved in a referendum in September 2025 and whose launch was postponed in June 2026, with the trust infrastructure now expected in the first half of 2027. Our Switzerland country page tracks the current status. The decision to let users bring their own credentials, the core of Clavid’s 2008 pitch, looks familiar. For where this fits in the bigger sequence, see the OpenID timeline and the guide to biometric login.
Based on the archived OpenID Europe posts of 2008. The status of the Swiss E-ID is given as of October 2026 and should be checked against official sources.
More in History
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.