August 26, 2008

OAuth Licensed, a Step on the Way to the Open Web

Specification are tricky creatures. On their own, they are only copyrightable. But on their own they are also not very interesting. Their value is in their implementations, and those are subject to patents. If you have been following the tech world over the past couple of year, you know that patents can be very risky to developers. The problem is that in order to implement specifications, the developer usually has to write code that uses some existing patents. It is practically impossible to know which patents are involved, but at a minimum, the developers need to know that the people who wrote the specification are not going to sue them.

Over the past 8 months we have been working to obtain the necessary protections for the community, to be able to freely implement the OAuth Core 1.0 specification without any fear of being sued by any of the people involved (or their employers). Unlike specifications done in standard bodies where Intellectual Property Rights (IPR) are established ahead of time and set the scope and terms of the work, community specifications start with ideas and goodwill. This is a fundamental difference and a requirement for future community work. The need for the Open Web Foundation grew out of the frustration of communities like OAuth and OpenID having to go through hell to obtain these legal protections. In the next few months, the Open Web Foundation will offer tools and help communities avoid this painful process and focus on writing good specifications, not legal contracts.

Some of you will notice the new addition to the OAuth specification – the License section! A short paragraph detailing the licensing terms of the specification and providing links to the legal agreements. That short addition took hundred of hours and the dedication of many individuals and companies. Guaranteeing the open availability of this work is critical for small and large companies alike. Not everyone cares about this the same way and there are already implementations of OAuth out there. IPR risk is something very specific to each company and its culture, but this effort will help provide equal access to this important building block. It is not absolute protection – there is no such thing – but it is pretty good!

The OAuth license has been signed by AOL, Citizen Agency, Google, Ma.gnolia, Pownce, Six Apart, Twitter, Wesabe, Yahoo!, and the individual contributors. I would like to personally thank everyone involved in making this happen. The Yahoo!, Google, and Six Apart legal teams contributed many hours to help, not only focused on their own needs, but the needs of the community as well. I also want to thank Gabe Wachob, DeWitt Clinton, David Recordon, Larry Halff, and Shreyas Doshi for their continued personal support of this effort. This might not be very sexy, but it is an extremely important step to ensure the continued success of the open web.

(And you all owe me a beer!)

Comments

TrackBack

TrackBack URL for this entry:   http://www.typepad.com/services/trackback/6a00e00993be88883300e5548096058834

» It's Official: Mashup Privacy Protocol OAuth Is Fair Game from ReadWriteWeb
OAuth, the open authorization protocol standard that will let users give limited access to their data to third party websites without giving away their passwords, crossed an important threshold tonight. All parties involved in building the spec have si... [Read More]

» OAuth licensingfinalized from OAuth
No doubt Eran Hammer-Lahav relished announcing the conclusion of the arduous IPR process for OAuth with the addition of a licensing statement now found on the specification, signed by AOL, Citizen Agency, Google, Ma.gnolia, Pownce, Six Apart, Twitter, ... [Read More]

Stay Informed

  • Want to stay informed about the recent developments in OAuth, Discovery, Open Web Foundation, and related topics? Subscribe today!.

Disclaimer

  • The opinions expressed in this blog are solely my own and do not necessarily reflect those of my employer. For more information read the full disclaimer.

Recent Comments

About

  • This is the technology blog of Eran Hammer-Lahav. A frequent contributor to OAuth, Discovery, XRD, and other emerging community-driven specifications and standards, I am currently working as Yahoo!'s Director of Standards Development. My personal blog is Half a Bee.

Copyright License

Creative Commons License.