SlideShare ist ein Scribd-Unternehmen logo
1 von 21
What is XAuth?
Xauth defined Extended Authentication,  an open platform for extending authenticated user services across the web.
EXTENDED AUTHENTICATION A proposed Web standard that detects which social networks the website visitor is already logged into
BENEFIT Enables the site to offer only the website visitor’s preferred sites as options for sharing instead of a long list of every possible sharing site
BENEFIT Facilitates including second-tier sharing services (such as Google Buzz) with greater ease Speeds page load time
HOW IT WORKS Participating services generate a browser token for each of their users.  The XAuth Token can be anything, so services have the flexibility to define whatever level of access they choose
HOW IT WORKS Publishers can then recognize when site visitors are logged in to those online services and present them with meaningful, relevant options. Users can choose to authenticate directly from the publisher site and use the service to share, interact with friends, or participate in the site's community.
IMPLEMENTATION Meebo is putting XAuth into its Meebo bar, which appears on a number of publisher websites
Xauth SUPPORTERS Google, Microsoft, Yahoo MySpace, Disqus and Meebo’s publishing partners including Time Inc. and MTV Networks
What about OAuth? Oauth is an  open protocol  to allow  secure API authorization  in a  simple  and  standard  method from desktop and web applications.
OAuth OAuth allows the User to grant access to their private resources on one site (called the Service Provider), to another site (called the Consumer, not to be confused with you, the User).
What about OpenID? While OpenID is all about using a single identity to sign into many sites,  OAuth is about giving access to your stuff without sharing your identity at all (or its secret parts).
OAuth OAuth attempts to provide a standard way for developers to offer their services via an API without forcing their users to expose their passwords 
Industry Protocols Google AuthSub AOL OpenAuth Yahoo BBAuth Upcoming API  Flickr API Amazon Web Services API 
Xauth vs. OAuth XAuth tells you  where to ask for OAuth from
Xauth and OAuth Example: XAuth tells a webpage "this is where the site visitor does social networking."
Xauth and OAuth Then,  OAuth is the way the user logs in there,  granting the site permission to access their info without seeing their password
Xauth COMPETITION ,[object Object],[object Object],[object Object]
FACEBOOK ,[object Object],[object Object],[object Object]
CHALLENGE Privacy: Enables third-party site to identify the services you belong to
[object Object],[object Object],[object Object],[object Object],[object Object]

Weitere ähnliche Inhalte

Ähnlich wie What is XAuth?

Social Network Intergration
Social Network IntergrationSocial Network Intergration
Social Network Intergration
Dinesh Kumar
 
OAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guessOAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guess
Mehdi Medjaoui
 

Ähnlich wie What is XAuth? (20)

Social Network Intergration
Social Network IntergrationSocial Network Intergration
Social Network Intergration
 
OAuth Android Göteborg
OAuth Android GöteborgOAuth Android Göteborg
OAuth Android Göteborg
 
Open authentication (oauth)
Open authentication (oauth)Open authentication (oauth)
Open authentication (oauth)
 
Technology for Teachers
Technology for TeachersTechnology for Teachers
Technology for Teachers
 
Facebook_Oauth
Facebook_OauthFacebook_Oauth
Facebook_Oauth
 
Facebook_Oauth
Facebook_OauthFacebook_Oauth
Facebook_Oauth
 
Building AJAX Applications Using Yahoo! Web Services
Building AJAX Applications Using Yahoo! Web ServicesBuilding AJAX Applications Using Yahoo! Web Services
Building AJAX Applications Using Yahoo! Web Services
 
Oauth 2.0
Oauth 2.0Oauth 2.0
Oauth 2.0
 
About OExchange
About OExchangeAbout OExchange
About OExchange
 
OAuth Tokens
OAuth TokensOAuth Tokens
OAuth Tokens
 
Openid & Oauth: An Introduction
Openid & Oauth: An IntroductionOpenid & Oauth: An Introduction
Openid & Oauth: An Introduction
 
Making Web 2.0 Real Part 2 - Rich Interfaces
Making Web 2.0 Real Part 2 - Rich InterfacesMaking Web 2.0 Real Part 2 - Rich Interfaces
Making Web 2.0 Real Part 2 - Rich Interfaces
 
O auth
O authO auth
O auth
 
OAuth
OAuthOAuth
OAuth
 
Oauth
OauthOauth
Oauth
 
OExchange Technical Intro
OExchange Technical IntroOExchange Technical Intro
OExchange Technical Intro
 
Twitter Update for Social Developers London - March 2013
Twitter Update for Social Developers London - March 2013Twitter Update for Social Developers London - March 2013
Twitter Update for Social Developers London - March 2013
 
OAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guessOAuth In The Real World : 10 actual implementations you can't guess
OAuth In The Real World : 10 actual implementations you can't guess
 
Office 365 Authentication Process (oAuth Service Integration) - iXora Tech Se...
Office 365 Authentication Process (oAuth Service Integration) - iXora Tech Se...Office 365 Authentication Process (oAuth Service Integration) - iXora Tech Se...
Office 365 Authentication Process (oAuth Service Integration) - iXora Tech Se...
 
Widget and Web Ecosystem - Updated
Widget and Web Ecosystem - UpdatedWidget and Web Ecosystem - Updated
Widget and Web Ecosystem - Updated
 

Kürzlich hochgeladen

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 

What is XAuth?

  • 2. Xauth defined Extended Authentication, an open platform for extending authenticated user services across the web.
  • 3. EXTENDED AUTHENTICATION A proposed Web standard that detects which social networks the website visitor is already logged into
  • 4. BENEFIT Enables the site to offer only the website visitor’s preferred sites as options for sharing instead of a long list of every possible sharing site
  • 5. BENEFIT Facilitates including second-tier sharing services (such as Google Buzz) with greater ease Speeds page load time
  • 6. HOW IT WORKS Participating services generate a browser token for each of their users. The XAuth Token can be anything, so services have the flexibility to define whatever level of access they choose
  • 7. HOW IT WORKS Publishers can then recognize when site visitors are logged in to those online services and present them with meaningful, relevant options. Users can choose to authenticate directly from the publisher site and use the service to share, interact with friends, or participate in the site's community.
  • 8. IMPLEMENTATION Meebo is putting XAuth into its Meebo bar, which appears on a number of publisher websites
  • 9. Xauth SUPPORTERS Google, Microsoft, Yahoo MySpace, Disqus and Meebo’s publishing partners including Time Inc. and MTV Networks
  • 10. What about OAuth? Oauth is an  open protocol  to allow  secure API authorization  in a  simple and  standard  method from desktop and web applications.
  • 11. OAuth OAuth allows the User to grant access to their private resources on one site (called the Service Provider), to another site (called the Consumer, not to be confused with you, the User).
  • 12. What about OpenID? While OpenID is all about using a single identity to sign into many sites, OAuth is about giving access to your stuff without sharing your identity at all (or its secret parts).
  • 13. OAuth OAuth attempts to provide a standard way for developers to offer their services via an API without forcing their users to expose their passwords 
  • 14. Industry Protocols Google AuthSub AOL OpenAuth Yahoo BBAuth Upcoming API Flickr API Amazon Web Services API 
  • 15. Xauth vs. OAuth XAuth tells you where to ask for OAuth from
  • 16. Xauth and OAuth Example: XAuth tells a webpage "this is where the site visitor does social networking."
  • 17. Xauth and OAuth Then, OAuth is the way the user logs in there, granting the site permission to access their info without seeing their password
  • 18.
  • 19.
  • 20. CHALLENGE Privacy: Enables third-party site to identify the services you belong to
  • 21.