Yahoo becomes an OpenID provider in 2008
In early 2008 Yahoo announced OpenID 2.0 support and opened a public beta provider for its members. How it worked, what the numbers meant and what came next.
HistoryPublished
In January and February 2008 Yahoo, one of the largest web portals of its day, switched on OpenID for its members. It was one of the first times that a company of that size made OpenID 2.0 available to millions of ordinary accounts. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to Yahoo, to the OpenID Foundation or to the former OpenID Europe Foundation.
What Yahoo announced
Reference sources date Yahoo’s announcement of OpenID 2.0 support to 17 January 2008. It covered two roles: Yahoo as an OpenID provider, vouching for its members to other sites, and Yahoo as a relying party, accepting OpenID logins itself. The provider side went into a public beta around the turn of the month. The community’s European blog reported on 2 February 2008 that Yahoo “has now launched the public beta” of its OpenID provider service, ready for any web service compatible with OpenID 2.0. For how the protocol itself worked, see OpenID 2.0: the original decentralised login.
What it meant for users
The pitch in the post was simple. Millions of existing Yahoo members could use their Yahoo ID to sign in at third-party sites, and the company claimed it had simplified the process so that users would not need to understand the “backend concept of OpenID”. The post added that the service was already open to users in 17 countries and that international editions were in preparation.
The design relied on provider-led login from the 2.0 specification, finalised only weeks earlier (December 2007: OpenID Authentication 2.0 is approved): users should not have to type a long web address. Instead, a user could just click a Yahoo option, sign in as usual and approve the transfer of limited information.
The big numbers
On 7 February 2008 the OpenID Foundation announced that Yahoo, Google, IBM, Microsoft and VeriSign had become its first corporate board members. In that release a Yahoo executive said the company had worked for a year with the Foundation on its intellectual property framework and on the final 2.0 specification, and was adopting OpenID for all 248 million active registered Yahoo users worldwide. The same release counted more than 10,000 sites with OpenID login and an estimated 350 million OpenID-enabled URLs. The board story is told in February 2008: Google, IBM, Microsoft and Yahoo join the OpenID Foundation.
Be careful with such numbers. An “OpenID-enabled URL” meant that an account could in principle be used as an OpenID, not that anyone had done so. Most Yahoo members did not know that they had an OpenID or what to do with it. The relevant measure for adoption was how many people signed in to a third-party site with it, and nobody published that.
What happened to Yahoo’s OpenID
Yahoo’s provider was one of several that arrived in 2008, followed by MySpace in the summer (MySpace announces OpenID support) and by Google and Windows Live ID in October (Google and Windows Live ID open up to OpenID). In the end, though, the major platforms promoted their own login buttons. Reference works report that Google and Yahoo discontinued active OpenID support over time, and the wider reasons are discussed in Why OpenID 2.0 faded. We could not verify an exact shutdown date for Yahoo’s service, so we do not give one.
Why this episode matters today
The Yahoo launch shows two patterns that recur in identity technology. A large platform can create adoption on paper in a day, but real use depends on whether the login is easier than the alternative. And once a technology gives control to users, platforms have little reason to promote it unless it brings them value. The same dynamics now shape the EU Digital Identity Wallet: see The EU Digital Identity Wallet explained for how law, rather than goodwill, is being used to create demand. Today the idea of “log in with a big provider” lives on in OpenID Connect. The full chronology is in the OpenID timeline.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.