Why OpenID 2.0 faded: five reasons it lost
OpenID 2.0 had big backers in 2008 and was almost gone a decade later. Five reasons: usability, a lopsided market, phishing, social login and the move to mobile.
HistoryPublished
OpenID 2.0 was approved in December 2007 and had Google, Yahoo, Microsoft, IBM and VeriSign on the board of its foundation by early 2008. A decade later it was a niche protocol. Nobody switched it off in one go. It faded because five weaknesses added up.
1. It was hard for ordinary people
The original idea was elegant for developers: your identity is a URL that you own. For ordinary users it was confusing. People did not know what an OpenID was, had to type a web address into a login box, and then were sent to another site. Many did not know that their existing email or blog account already provided one. Sites tried to help with a row of provider logos, but a row of logos asks the user to remember which provider they used. Our page on OpenID 2.0 describes the flow.
2. A lopsided market
OpenID worked only if two sides joined. Providers issued OpenIDs, and relying parties accepted them. The big companies were willing to be providers, which gave a great many people an OpenID that they never used. But a website gained little from accepting OpenID unless many visitors had one and cared to use it, while visitors had little reason to use it unless many sites accepted it. The chicken-and-egg problem was never solved. Companies were happy to issue identities but were far less keen to accept someone else’s.
3. Phishing
An OpenID login sends you from the website to your provider’s page and back. If a malicious site sent you to a look-alike provider page, you could hand over your credentials without noticing. Users had no reliable way to tell the real page from a fake, and the protocol itself offered none. The community was aware of the problem. As early as February 2007 Microsoft announced work with other vendors on combining OpenID with its CardSpace system, with a particular focus on phishing-resistant authentication. That work did not reach the mainstream, and CardSpace was discontinued. Real phishing resistance arrived later with FIDO2 and passkeys.
4. Social login won
In 2008 Facebook began offering a single branded button that delivered a profile and a social graph. It was simpler for users and richer for sites. The contest is told in Facebook Connect vs OpenID. Once Facebook, Google and Twitter had their own buttons, a generic standard looked like a worse offer.
5. The web moved to apps and APIs
OpenID 2.0 was built for browsers and had no good answer for mobile apps and for programs calling APIs on a user’s behalf. OAuth did. By the early 2010s developers were building on OAuth 2.0 and treating identity as an add-on. The OpenID Foundation responded with a new protocol, OpenID Connect, finished in February 2014, which put identity on top of OAuth. The change is told in From OpenID to OpenID Connect.
How it ended
The decline shows in the shutdowns. The hosted provider MyOpenID closed in February 2014, after its operator announced the move in September 2013. Blogger dropped OpenID in 2018, and Stack Overflow ended its OpenID support in March 2018, citing insufficient usage compared with other login options. Google, which had been among the first big providers, moved its login to OpenID Connect and retired its OpenID 2.0 endpoint over the following years. Some niche uses lasted longer, and the Steam platform, for example, became an OpenID provider for third-party sites in 2010. We have not checked whether such uses are unchanged today.
What went right
OpenID changed how developers thought. It established vocabulary still in use: relying party, provider, discovery, attribute exchange. It brought the biggest internet companies to an open standards table. And its core idea, that a user should be able to prove who they are without handing a password to every site, lives on in single sign-on and in the wallet.
What the wallet must learn
The EU wallet starts with something OpenID never had: a law that makes banks and large platforms accept it, and a state-backed credential. But usability, relying-party adoption and phishing resistance remain the three things to watch. We take them one at a time in Five lessons from OpenID for the EU wallet. The full chronology is in the OpenID timeline.
Dates from public records of the OpenID Foundation and the providers named; checked October 2026.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.
Google, IBM, Microsoft, Yahoo join the OpenID Foundation
On 7 February 2008 Google, IBM, Microsoft, VeriSign and Yahoo became corporate board members of the OpenID Foundation. What it meant and how to read the data.
Jabber.org and OpenID in 2008: XMPP meets web login
In March 2008 the Jabber.org website began accepting OpenID logins. What that meant for open instant messaging, and what became of Jabber.org since.