Hueniverse
  • Home
  • Node.js
  • OAuth
  • XRD
  • WebFinger
  • Discovery
  • Got Questions?
Subscribe

OAuth

Updated on July 26th, 2012

OAuth Shine

OAuth 1.0

The OAuth 1.0 guide covers the protocol as defined by RFC 5849 and includes many corrections and improvements from previous blog posts and the original Beginner’s guide. To stay up to date about all things OAuth, check this page or subscribe.

  • Introduction
  • History
  • Terminology
  • Specification Structure
  • Protocol Workflow
  • Security Framwork
  • Authentication

OAuth 2.0

OAuth 2.0 is a work in progress at the IETF. I am no longer involved in the 2.0 effort and have withdraw my name and support from it.



Recent posts on the subject:

  • #fuckoauth @realtimeconf
  • On Leaving OAuth
  • OAuth 2.0 and the Road to Hell
  • OAuth 1.0 Blog Cleanup
  • OAuth 2.0 Redirection URI Validation
  • OAuth Bearer Tokens are a Terrible Idea
  • More OAuth Nonsense
  • OAuth 2.0 (without Signatures) is Bad for the Web
  • Twitter a Hot Princess, Google an Empty Castle
  • All This Twitter OAuth Security Nonsense
  • Introducing OAuth 2.0
  • Open Questions About OAuth 2.0 Authentication
  • What's going on with OAuth?
  • 2009 Year-End Status Report
  • Sneak Peek: The Authoritative Guide to OAuth 1.0
  • Resources & Guides
    • The OAuth 1.0 Guide
      The OAuth 1.0 Guide
  • Featured Posts
    • How We Interact With the Unknown
      How We Interact With the Unknown 8 Comments
    • The Discovery Protocol Stack, Redux
      The Discovery Protocol Stack, Redux 3 Comments
    • Implementing WebFinger
      Implementing WebFinger 12 Comments
    • Explaining the OAuth Session Fixation Attack
      Explaining the OAuth Session Fixation Attack 21 Comments
    • Introducing 'Sign-in with Twitter', OAuth-Style
      Introducing 'Sign-in with Twitter', OAuth-Style "Connect" 19 Comments
  • Recent Posts
    • Hiring Engineers, a Process
      35 Comments
    • hapi hapi joi joi
      0 Comments
    • hapi, a Prologue
      3 Comments
    • #fuckoauth @realtimeconf
      7 Comments
    • On Leaving OAuth
      23 Comments
    • OAuth 2.0 and the Road to Hell
      153 Comments
    • You, Me, and Node @WalmartLabs
      0 Comments
    • Sled, Yahoo!, and Moving On
      6 Comments
    • Is the Party Winding Down at Facebook?
      3 Comments
    • Netflix Forcing the Issue Too Soon
      3 Comments
    RSS Feed »
  • Categories
    • Architecture (3)
    • Cartoons (7)
    • Discovery (36)
    • Featured (5)
    • Guest Writer (9)
    • Microblogging (20)
    • Node.js (9)
    • OAuth (67)
    • Open Web (28)
    • OpenID (22)
    • Opinions (2)
    • Personal (4)
    • Recap (7)
    • Sled (7)
    • Social Web (9)
    • Startup (18)
    • Sunday Reading (8)
    • Uncategorized (2)
    • WebFinger (8)
    • Work (8)
    • XRD (17)
  • Copyright License
    © 2006-2010 Hueniverse, LLC.
    The site articles are licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License.

    Creative Commons License

About hueniverse

This is the technology blog of Eran Hammer. A frequent contributor to OAuth, Discovery, XRD, and other emerging open specifications and standards. The opinions expressed in this blog are solely of their authors and do not necessarily reflect those of their employers. For more information read the full disclaimer.


hueniverse powered by WordPress and hosted by
(mt)