openideurope.eu

Why OpenID 2.0 faded: five reasons it lost

OpenID 2.0 had big backers in 2008 and was almost gone a decade later. Five reasons: usability, a lopsided market, phishing, social login and the move to mobile.

HistoryPublished

OpenID 2.0 was approved in December 2007 and had Google, Yahoo, Microsoft, IBM and VeriSign on the board of its foundation by early 2008. A decade later it was a niche protocol. Nobody switched it off in one go. It faded because five weaknesses added up.

1. It was hard for ordinary people

The original idea was elegant for developers: your identity is a URL that you own. For ordinary users it was confusing. People did not know what an OpenID was, had to type a web address into a login box, and then were sent to another site. Many did not know that their existing email or blog account already provided one. Sites tried to help with a row of provider logos, but a row of logos asks the user to remember which provider they used. Our page on OpenID 2.0 describes the flow.

2. A lopsided market

OpenID worked only if two sides joined. Providers issued OpenIDs, and relying parties accepted them. The big companies were willing to be providers, which gave a great many people an OpenID that they never used. But a website gained little from accepting OpenID unless many visitors had one and cared to use it, while visitors had little reason to use it unless many sites accepted it. The chicken-and-egg problem was never solved. Companies were happy to issue identities but were far less keen to accept someone else’s.

3. Phishing

An OpenID login sends you from the website to your provider’s page and back. If a malicious site sent you to a look-alike provider page, you could hand over your credentials without noticing. Users had no reliable way to tell the real page from a fake, and the protocol itself offered none. The community was aware of the problem. As early as February 2007 Microsoft announced work with other vendors on combining OpenID with its CardSpace system, with a particular focus on phishing-resistant authentication. That work did not reach the mainstream, and CardSpace was discontinued. Real phishing resistance arrived later with FIDO2 and passkeys.

4. Social login won

In 2008 Facebook began offering a single branded button that delivered a profile and a social graph. It was simpler for users and richer for sites. The contest is told in Facebook Connect vs OpenID. Once Facebook, Google and Twitter had their own buttons, a generic standard looked like a worse offer.

5. The web moved to apps and APIs

OpenID 2.0 was built for browsers and had no good answer for mobile apps and for programs calling APIs on a user’s behalf. OAuth did. By the early 2010s developers were building on OAuth 2.0 and treating identity as an add-on. The OpenID Foundation responded with a new protocol, OpenID Connect, finished in February 2014, which put identity on top of OAuth. The change is told in From OpenID to OpenID Connect.

How it ended

The decline shows in the shutdowns. The hosted provider MyOpenID closed in February 2014, after its operator announced the move in September 2013. Blogger dropped OpenID in 2018, and Stack Overflow ended its OpenID support in March 2018, citing insufficient usage compared with other login options. Google, which had been among the first big providers, moved its login to OpenID Connect and retired its OpenID 2.0 endpoint over the following years. Some niche uses lasted longer, and the Steam platform, for example, became an OpenID provider for third-party sites in 2010. We have not checked whether such uses are unchanged today.

What went right

OpenID changed how developers thought. It established vocabulary still in use: relying party, provider, discovery, attribute exchange. It brought the biggest internet companies to an open standards table. And its core idea, that a user should be able to prove who they are without handing a password to every site, lives on in single sign-on and in the wallet.

What the wallet must learn

The EU wallet starts with something OpenID never had: a law that makes banks and large platforms accept it, and a state-backed credential. But usability, relying-party adoption and phishing resistance remain the three things to watch. We take them one at a time in Five lessons from OpenID for the EU wallet. The full chronology is in the OpenID timeline.

Dates from public records of the OpenID Foundation and the providers named; checked October 2026.

More in History