« Test Test Test | Main | The Yahoo! OpenID t-shirts are here »

April 24, 2008

Yahoo! announces plans to adopt OAuth as part of the Yahoo! Open Strategy

If you've been following some of the posts on this blog, you've hopefully drank the kool-aid on the view of identity standards like OpenID and OAuth as the fundamental building blocks for more interesting and interoperable apps on the web. At Yahoo!, we've been thinking hard about the value of adopting open standards instead of pushing proprietary products that have been in existence prior to these standards. We have also been talking to and working with the OAuth and OpenID communities on technical, business, and legal fronts. To put our money where our mouth is, in January 2008, we launched the public beta of the Yahoo! OpenID Provider, with an emphasis on significantly improving the OpenID user experience and allowing users to have the convenience of a single identity without the burden of understanding the technical underpinnings of OpenID.

Today, Ari Balogh (new Yahoo! CTO - see video below) publicly announced the broader Yahoo! Open Strategy at the Web 2.0 Expo keynote session (see Cody Simms' post on the Yahoo! Developer Network blog for the juicy details). A key element of this announcement is that, in the not-too-distant future, we will be supporting OAuth as THE STANDARD for authenticated API access for 3rd party developers that want to innovate on top of Yahoo!'s incredible assets and diverse array of services. This auth mechanism will work with web applications, thick-client (installed) applications, and embedded applications! For those who are not familiar with OAuth, it is a community-driven standard that allows 3rd party developers to securely access APIs that expose user data residing on services like Yahoo!. This is done in a way that:

  • the user doesn't have reveal his Yahoo! password to the 3rd party application - A good general practice
  • the 3rd party application only has access to the stuff that is necessary for its use, and nothing else (eg. only access my Address Book, and not my Mail or my billing information) - Scoped access is better than global, unfettered access to all my data
  • the user can easily revoke access if he no longer trusts or uses the 3rd party application - User is always in control

If you are familiar with Yahoo! BBAuth, you can think of OAuth as a standard way of doing what BBAuth enables. As a developer who's building interesting things on top of Yahoo! APIs and APIs of other companies that support OAuth, you will not need to write a whole lot of custom code to integrate with 'N' different authentication APIs which all essentially do the same thing. Besides, you can take advantage of open source client libraries for OAuth to reduce the time to implement the auth component of your service or mashup - instead, you can focus that time on building features that really delight your users.

Our announcement today represents a big win for the OAuth community's efforts and is a harbinger of even more interesting things in the near future. As always, stay tuned for more...

Updates:

Heres a video of Ari's Y!OS announcement:

Techcrunch coverage of The New Yahoo!

See Neal Sample's post on Yodel Anecdotal

Heres Neal's talk at Web 2.0 Expo:

See Charlene Li's write-up of Yahoo!'s Open Strategy announcement

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/2750204/28468216

Listed below are links to weblogs that reference Yahoo! announces plans to adopt OAuth as part of the Yahoo! Open Strategy:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Rock on! Great news!! ;)

Post a comment

If you have a TypeKey or TypePad account, please Sign In

About Me

Me Everywhere

May 2008

Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Twitter Updates

    follow me on Twitter

    Recent Visitors

    Shared items

    Flickr

    • www.flickr.com
      This is a Flickr badge showing public photos from santhoshreyas. Make your own badge here.

    Miscellaneous Junk

    AddThis Social Bookmark Button

    IIW

    • IIW2008 Registration banner