







The purpose of the Federated Identity Community Group is to provide a forum focused on incubating web features that will both support federated identity and prevent untransparent, uncontrollable tracking of users across the web. While the community group will take privacy concerns into consideration, these concerns will be balanced against the need to explore innovative ideas around federated authentication on the web.
IIW – Internet Identity Workshop
The Internet Identity Workshop — where the identity community meets to discuss and advance digital identity.

Federated Credential Management (FedCM) API - Web APIs | MDN
The Federated Credential Management API (or FedCM API) provides a standard mechanism for identity providers (IdPs) to make identity federation services available on the web in a privacy-preserving way, without the need for third-party cookies and redirects. This includes a JavaScript API that enables the use of federated authentication for activities such as signing in or signing up on a website.

IndieAuth
IndieAuth is a federated login protocol for Web sign-in, enabling users to use their own domain to sign in to other sites and services. IndieAuth can be used to implement OAuth2 login AKA OAuth-based login.
WebID - W3C Wiki
The W3C is still exploring better ways to do authentication, for example in the 2014 workshop on authentication. The WebID is a Community Group, and anyone can start a Community Group. A Community Group does not necessarily reflect the endorsement of the W3C, but we encourage grassroots communities to experiment with technology that may become a future standard.
2026 List of Identity and Related Conferences and Standards Development Events
Agenda and minutes of meetings of the Federated Identity Community Group - fedidcg/meetings
EFFecting Change: How to Build a Decentralized Web That Truly Works for All
Open Social Web ID - Erlend’s notes
Approaching a shared method of single sign-on for the entire open social web.
SyRA: Sybil-Resilient Anonymous Signatures with Applications to Decentralized Identity
We study Sybil-Resilient Anonymous (SyRA) signatures, a cryptographic primitive that enables credentialed users to generate, on demand, unlinkable pseudonyms tied to any given context, and issue signatures on behalf of these pseudonyms. Concretely, SyRA allows a distributed issuer to turn any legacy identity or personhood identifier, possibly of low entropy, into a unique associated cryptographic key of high pseudoentropy, for use in generating signatures for any given context. Sybil-resilient anonymous signatures achieve three main objectives: 1) Sybil resilience: every user is entitled to at most one digital identity, 2) anonymity: no information about the user’s real identity is leaked, and 3) non-interactive context switching: users can create on their own at most one credential for any given context in a manner that is unlinkable across contexts. We conceptualize the SyRA primitive as an ideal functionality in the Universal Composition (UC) setting and put forth SASSI, an efficient, pairing-based construction that realizes it by utilizing two levels of verifiable random functions (VRFs), a design which may be of independent interest. The first level consists of threshold VRF issuance of a user’s unique secret key tied to their real-world identifier. The second level allows a user to create signatures for each context, under a unique pseudonym per context. Compared to prior cryptographic tools capable of realizing SyRA, SASSI has the unique feature that issuers are stateless and hence do not need to retain any information about past user interactions, a relevant property for a decentralized implementation. We overview various applications of SASSI in multiparty systems, such as cryptocurrency account management and airdrops, e-voting (e.g., for decentralized governance), and privacy-preserving regulatory compliance (e.g., AML/CFT checks). In the context of creating addresses for digital assets, SyRA signatures enable users to embed their legacy identity into their address in a manner that protects their privacy for each application with which they interact. We demonstrate the practicality of SASSI by providing an implementation and performance evaluation of our construction.

The web should remain anonymous by default | The Mozilla Blog
The unique architecture of the web enables a much higher degree of user privacy than exists on other platforms. Many factors contribute to this, but an ess

PACT: Anonymous Credentials for the Web – Mozilla Hacks - the Web developer blog
A deeper look at PACT: a new initiative to tackle the rising tide of CAPTCHAs on the web whilst keeping the web open and preserving user's privacy.

Exposed Persona Frontend Reveals Extensive Biometric Surveillance Stack Behind Age Verification - ID Tech
Security researchers investigating Discord’s age-verification implementation have discovered a publicly exposed frontend belonging to Persona Identities, Inc., revealing that the identity-verification vendor’s platform performs far more extensive checks than users […]

Once you experience shared lexicons and the benefits of a single portable identity, it feels like a new open network. But the most important part is that it practically works as an extension of the web. We can add social features to our websites without even mentioning atproto. Frictionless adoption
P(aul) Frazee
The Atmosphere is a new open network. The features: - Your account works on all atmosphere apps - You can switch to a new provider with no fuss - Easy to make your own apps on it - Works great with personal websites And, Bluesky is an atmosphere app.
We're getting close! atlogin.net is a start on the identity side, and we just launched declarative node sharing which lets you share groups of devices with arbitrary outside identities (without them joining your tailnet). tailscale.com/docs/features/declarative-nod…
ATLogin - OIDC for ATProto/Bluesky
atlogin.netHeeey, look, it's me! I'm super hyped to announce that @bsky.app have given me a grant to work on the standards for the Federated Credential Management API (or FedCM) to make them really work for all decentralized web applications.
AT Protocol Developers
We're so excited to support @thisismissem.social's work bringing FedCM to the open social web! atproto.com/blog/working-to-decentralize-…
@thisismissem.social @divy.zone and I recently went through an exploration of how the browser can help you login to websites with atproto accounts. We recently presented to the FedID CG and here is a sneak peek in case you couldn't join! This is early but we'd love your input before we go too far!