Navigation

Recent site activity

Public Documentation

This site contains public information from Google that is shared with open source communities working on projects in the identity space
To be notified of new posts to this site, or changes, please subscribe to the blog at http://oauthgoog.blogspot.com/

Overlap of OAuth, OpenID, SAML, SaaS, 2ndFactorAuth, InfoCards, OpenSocial, Portable Contacts...

Usability Research on Federated Login
Research Summary
Google's UI Research on login boxes that support federated login (Originally presented at the OpenID Concent Advisory Council on September 18, 2008 and announced in this blog post)
Information on another approach that simply asks for Email in the login box
Slide deck on the background of Google's FedLogin research
Additional UX feedback for sites that require unique usernames
Working prototypes of this UI and others
Overview of hybrid onboarding
UX research on desktop apps using federated login and/or OAuth
Auto-detecting OAuth approval from a desktop app
Videos of that desktop prototype with different federated login and strong authentication mechanisms
Formal announcement (part 1 and part 2) of Google's OpenID IDP, including documentation and discussion group
Announcement of Google's support for the PopUp style UI
Yahoo UX Research on their IDP endpoint
Thoughts on combining Google & Yahoo OpenID UX research
In-depth article by a journalist covering the usability of OpenID
Early UX notes on browser integration for federated login (especially IDP discovery) [See IIW 2009b notes]
An early draft proposal for a Personal Discovery Service to bootstrap IDP discovery without a browser extension
A draft of a Central Discovery Service specific to federated login is also available (or see slide version)
Suggested best-practices for identity providers to protect user passwords from dictionary attacks
Early UX notes on strong authentication
Early UX notes on privacy and authentication
Early UX notes on timeouts and password reprompts

Google authored articles on OAuth


Google APIs accessible via OAuth
Google Data API documentation (Apps, Base, Blogger, Calendar, Code Search, Contacts, Finance Portfolio, Health, Notebook, Spreadsheets, Picasa Web Albums, Documents, Webmaster Tools, YouTube, etc.)
Documentation on OAuth Authentication for Web Applications and Using OAuth with the Google Data API Client Libraries

Hybrid Protocol (OAuth + OpenID)
Business Goals
Collaborative site for protocol development (Step2)
Jan 29 2009 Google announcement of hybrid support
Demo of hybrid protocol (the source is also available)
Proposal for an OpenID OAuth extension (spec)
Proposal for an OAuth extension Supporting Unregistered Consumers (spec)
Protocol Description (Archival interest only, superseded by the spec proposals above)
Extended Association Protocol
Presentation on Hybrid Protocol

OAuth Proxy
Presentation on OAuth Proxy
Blog post on oauth.net - including proposal for key rotation and gadget extension
OAuth Proxy to SSO Integration Guide

Two Legged OAuth
Google I/O 2009 presentations on
Enterprise use of 2-legged OAuth (see Part 2 of slides or video)
Enterprise use of GData APIs with 2-legged OAuth [coming end of May]

OAuth + Google Apps Engine
Sample app that runs on Google Apps Engine and connects to Google Health via OAuth, including open source code

IDP as a Service (OpenID & SAML)
See Part1 of slides or video

Events
Gartner Identity and Access management Summit 2009 (slides of Eric Sachs keynote)
Microsoft OpenID CTP Usability summary
SOUPS
2009 (Symposium on Usable Privacy and Security) invited talk on OAuth and OpenID (slides)
Google I/O presentations in May 2009 (session videos are available)
IIW 2009a
in May, 2009 (see suggested list of OpenID sessions)
UX Summit on Feb 10, 2009
The 92% success demo
IIW 2008b on Nov 10-12, 2008
OpenID/OAuth UX Summit on October 20, 2008
Google presentation on Background of Federated Login research
Yahoo presentation on IDP user interface
MySpace presentation on OAuth + Hybrid approval page
Digital Identity World on September 10, 2008
Presentation on OAuth and WS-Trust
OAuth Summit on June 26, 2008
Announcement of OAuth for all Google Data APIs (and MySpace's similar announcement the same day)
Presentation on OAuth+Google Health
Presentation on OAuth Proxy
Presentation on Hybrid Protocol
Presentation on OAuth+OpenSocial


Google Contacts (including our E-mail usernames @google.com)
Google Security Product Managers: Eric Sachs <esachs> and Yariv Adan <yariv>
Google security engineers: Dirk Balfanz <balfanz>, Breno de Medeiros <breno>, Brian Eaton <beaton>




Attachments (2)

  • myspace_usability_summit_preso.pptx - on Oct 22, 2008 4:31 PM by Eric Sachs (version 1)
    372k Download
  • openid_uxsummit_2008Oct20.ppt - on Oct 22, 2008 12:55 PM by Eric Sachs (version 1)
    1932k Download