<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2010:/1/tag:www.readwriteweb.com,2008://1.6661-</id>
  <updated>2010-03-01T17:05:17Z</updated>
  <title>Comments for Mashups: Google&apos;s Adoption Makes oAuth a Must Have for All Apps</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=6661" title="Mashups: Google's Adoption Makes oAuth a Must Have for All Apps" />
    <published>2008-06-27T18:31:55Z</published>
    <updated>2008-06-27T19:58:05Z</updated>
    <title>Mashups: Google&apos;s Adoption Makes oAuth a Must Have for All Apps</title>
    <summary>Open standard based user authentication protocol oAuth has now been implemented across all Google Data APIs, quickly offering this young standard for easy mashups more market validation than it&apos;s ever had before. Eight months ago we wrote about the launch of oAuth 1.0, asking if the standard would lead to a flood of mashups across...</summary>
    <author>
      <name>Marshall Kirkpatrick</name>
      <uri>http://www.readwriteweb.com</uri>
    </author>
    
    <category term="Mashups" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/oauthlogo.jpg">Open standard based user authentication protocol <a href="http://oauth.net">oAuth</a> has now been implemented across all <a href="http://code.google.com/apis/gdata/">Google Data APIs</a>, quickly offering this young standard for easy mashups more market validation than it's ever had before.  </p>

<p>Eight months ago we wrote about <a href="http://www.readwriteweb.com/archives/oauth_one.php">the launch of oAuth 1.0</a>, asking if the standard would lead to a flood of mashups across the web.</p>]]>
      <![CDATA[<p>A standard method of authenticating users across different services means that mashup builders need only write one authentication process, then apply it to all data sources that support the standard.  That's hot, and it's now spreading faster around the web than we thought.  We discuss what this means for users below.</p>

<h2>Google's Support</h2>

<p>Last night the <a href="http://googledataapis.blogspot.com/2008/06/oauth-for-google-data-apis.html">Google Data API blog</a> announced that oAuth is now available for all Google Data APIs, everything from Gmail contacts to Google Calendar to Docs to YouTube.  This means that 3rd party app developers now have one easy, standardized and secure way to authenticate that their users really own the Google accounts they say they do - <em>without the apps asking users for their Google passwords</em>. That data from Google can then be mashed up with any other application interested in leveraging it.  </p>

<p>Google had included oAuth into the OpenSocial framework, but there was little indication that app developers were making use of it.  Google's recently launched FriendConnect offered website developers disappointingly little access to their users' data - partitioning the Google functionality into an iframe inside participating pages.</p>

<h2>Other Support</h2>

<p>We've wondered recently whether oAuth was just a good idea that wasn't really gaining any traction.  The list of sites with live oAuth support has been much smaller than we hoped.  Now that's changing fast.  <a href="http://photobucket.com">PhotoBucket</a> offers oAuth support and today <a href="http://smugmug.com">SmugMug</a> announced it as well.</p>

<p>We expect to see oAuth authenticating and relying parties spring up all around the web now that coveted Google user data is available through oAuth.</p>

<h2>What This Means for Users</h2>

<p>There is now no good reason for new applications to ask you for your Gmail username and password in order to access your list of contacts.  Don't give it to them - there's a standard, approved way for them to access that data now that doesn't require giving them unlimited access to your entire account.</p>

<p>Apps that don't use the approved Google user authentication method in short order will be acting like a mail carrier who says they have to have a key to the inside of your house to pick up your mail because they aren't familiar with the mailbox on the front porch.</p>

<p>Furthermore, we as users can now expect a thrilling new wave of mashup options that can take secure advantage of our Google data.  Google's adoption of oAuth is one of the most significant, tangible moves in support of authentic data portability that we've seen in a long time.  App developers should be tripping over each other to make use of this data so that our use of their apps can be made richer, more powerfully useful and engaging.  While they are developing to take advantage of Google's oAuth APIs, why not offer some oAuth back out to the world as well?  Google's validation of the standard should start a snowball of standards enabled mashups.</p>

<p>We're very excited that Google has taken this step to un-silo our data and support the mutually beneficial ecosystem of mashup developers and users.  We're very happy too for the community of <a href="http://oauth.net">oAuth</a> supporters, who have done a great job building and spreading something so needed around the web.  Today is a good day for the future of the web.</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58980</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58980" />
    <title>Comment from Tinu on 2008-06-27</title>
    <author>
        <name>Tinu</name>
        <uri>http://freetraffictip.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://freetraffictip.com">
        <![CDATA[<p>This *is* pretty huge news. Gonna have a domino effect on integrating Google into our lives -- for those of us who use Google now. I wonder how many folks will have a Google account just to be able to use this capability... I started out with Gmail and now I can't Not have a Google account. I'd be professionally disfunctional.</p>]]>
    </content>
    <published>2008-06-27T19:32:38Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58981</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58981" />
    <title>Comment from Peat Bakke on 2008-06-27</title>
    <author>
        <name>Peat Bakke</name>
        <uri>http://friendfeed.com/peat</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/peat">
        <![CDATA[<p>Fantastic!</p>

<p>oAuth is a huge enabler for the "enterprise 2.0" community, where security and control are of much higher concern than for most of us recreational/social web nerds.</p>

<p>Not sharing personal passwords is a good thing.  Selective sharing of data and capabilities is a good thing.  oAuth means that two parties who do not trust each other can still collaborate to solve bigger problems.  That's a very good thing.</p>

<p>Good for Google, PhotoBucket, and SmugMug.  Hopefully Yahoo and Facebook climb on board soon.</p>]]>
    </content>
    <published>2008-06-27T19:44:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58982</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58982" />
    <title>Comment from Lars Teigen on 2008-06-27</title>
    <author>
        <name>Lars Teigen</name>
        <uri>http://secondbrain.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://secondbrain.com/">
        <![CDATA[<p>This is a significant development - especially for services like us that build on en ecosystem of internet services.</p>]]>
    </content>
    <published>2008-06-27T20:20:54Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58984</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58984" />
    <title>Comment from Eran Hammer-Lahav on 2008-06-27</title>
    <author>
        <name>Eran Hammer-Lahav</name>
        <uri>http://hueniverse.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://hueniverse.com">
        <![CDATA[<p>MySpace also had a big announcement using OAuth yesterday. We had a pretty amazing turnout for the OAuth Summit yesterday with representatives from Yahoo!, Google, AOL, MySpace, Microsoft, Salesforce, Facebook, LinkedIn, and many others talking about OAuth!<br />
</p>]]>
    </content>
    <published>2008-06-27T20:31:20Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58986</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58986" />
    <title>Comment from Voyagerfan5761 on 2008-06-27</title>
    <author>
        <name>Voyagerfan5761</name>
        <uri>http://friendfeed.com/voyagerfan5761</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/voyagerfan5761">
        <![CDATA[<p>Now we have to wait for sites that currently ask for your Google Account credentials to update to use oAuth...</p>]]>
    </content>
    <published>2008-06-27T20:48:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:58988</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c58988" />
    <title>Comment from michaellambie.org on 2008-06-27</title>
    <author>
        <name>michaellambie.org</name>
        <uri>http://michaellambie.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://michaellambie.org">
        <![CDATA[<p>A great achievement. This also helps push along the message of DataPortability. I'm glad to see google taking initiative. </p>

<p>I suppose Plaxe will have to follow suit shortly as they have a fair penetration in the contact importer service market.</p>]]>
    </content>
    <published>2008-06-27T21:16:32Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:59007</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c59007" />
    <title>Comment from Stepan Mazurov on 2008-06-27</title>
    <author>
        <name>Stepan Mazurov</name>
        <uri>http://friendfeed.com/vulpes</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/vulpes">
        <![CDATA[<p>Yes, YES YEEEEEEEESSSSS! Finally</p>]]>
    </content>
    <published>2008-06-28T06:12:23Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:59008</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c59008" />
    <title>Comment from Stepan Mazurov on 2008-06-27</title>
    <author>
        <name>Stepan Mazurov</name>
        <uri>http://friendfeed.com/vulpes</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/vulpes">
        <![CDATA[<p>On an unrelated note, why can't I go to the digg story from friendfeed? Whats up with that...</p>]]>
    </content>
    <published>2008-06-28T06:13:01Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:59011</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c59011" />
    <title>Comment from sunny beach on 2008-06-28</title>
    <author>
        <name>sunny beach</name>
        <uri>http://sunnybeachrealestate.net/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://sunnybeachrealestate.net/">
        <![CDATA[<p>more importantly, their API is compatible with just about every web and local application development language: <a href="http://oauth.net/code/" rel="nofollow">http://oauth.net/code/</a></p>]]>
    </content>
    <published>2008-06-28T08:39:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.6661-comment:59078</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.6661" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_oauth.php#c59078" />
    <title>Comment from Ruben Zevallos Jr. on 2008-06-29</title>
    <author>
        <name>Ruben Zevallos Jr.</name>
        <uri>http://www.direito2.com.br</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.direito2.com.br">
        <![CDATA[<p>Is very good to know that's a very good know this new API... I'll check and try it... </p>]]>
    </content>
    <published>2008-06-30T04:19:51Z</published>
  </entry>

</feed>