#FedCM

2025-09-11

#FedCM is a proposed standard API for frictionless, privacy-preserving 𝐟𝐞𝐝𝐞𝐫𝐚𝐭𝐞𝐝 𝐥𝐨𝐠𝐢𝐧 on the web.

👉 Simplifies login for both 𝐮𝐬𝐞𝐫𝐬 & 𝐝𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬.
✅ Already supported in 𝐂𝐡𝐫𝐨𝐦𝐢𝐮𝐦 𝐛𝐫𝐨𝐰𝐬𝐞𝐫𝐬.

📰 Dive deeper in this #InfoQ article by Dan Moore: bit.ly/4n9BKcY

#WebDevelopment #SoftwareArchitecture #SoftwareDevelopment

2025-08-02

Awesome to see Shop using #FedCM in the wild!

Johannes Ernstj12t@j12t.social
2024-09-26

What's a good example for #FedCM in the wild? Are there any yet?

FedCM=Federated Credential Management developer.mozilla.org/en-US/do

2024-09-06

Indie social sign-in could go mainstream
blog.erlend.sh/indie-social-si
submitted by erlend_sh to fediverse3 points | 0 commentshttps://blog.erlend.sh/indie-social-sign-in-could-go-mainstreamBack in June I wrote about an exciting confluence of digital auth tech:
(1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .
In short, it is now easier than ever to log into web applications using

Erlend Sogge Heggenerlend@writing.exchange
2024-09-06

Back in June I wrote about an exciting confluence of digital auth tech:

(1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .

In short, it is now easier than ever to log into web applications using your own website as an identity provider. Or at least, it would be, if your favorite web apps supported these agency-enhancing technologies.

blog.erlend.sh/indie-social-si

#opensource #indieweb #identity

2024-07-30
Anyone interested in single sign-on / #SSO? Want a new toy to play with? I've been experimenting with it recently, and now I've got something to share: an experimental demo of how a "Sign in with the Fediverse" mechanism might work.

If you have a Mastodon or Hubzilla account, or an IndieAuth-style self-hosted identity, I'd like to invite you to try and sign in to my test site at login.mythik.co.uk.

Headline features:
  • User authentication/authorization based on the Ory tools.
  • Supports signing in using an existing Fediverse (or other) account - or one you host yourself
  • Open source - well, not yet, but it could be, if people are interested in it
  • Written by a non-expert! Woefully insecure! All manner of attacks, just waiting to be found! Invite your security expert friends to the party, and laugh together at the n00b! Fun for all the family!

Supported identity providers include:

(There's a chance Streams might work, too.)

Protocols supported:

If you can get it to work - share a screenshot and let me know what you think!

(I'll try to keep this running for a while, but I can't guarantee it - partly because I haven't finished trying to attack it yet. If I have to take it down for some reason, I'll edit this post to say so.)
2024-06-17

Just learned about the "Federated Credential Management API" #FedCM - a new proposal that adds browser support for managing delegated authentication workflows #OAuth #OIDC. It already looks great, but could be expanded with user-centric identity provider registration for more decentralization, as explained here: liquid.surf/2024/2/7/Can-FedCM

Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2024-06-14

Ever wondered if #FedCM supports #authorization ? It's coming!
Starting in Chrome 126, you can sign up for an origin trial and try it on your domain with the Continuation API. Along with the button flow we've introduced in the previous announcement, FedCM based sign-in flow will become even more streamlined. There are a few more exciting updates as well.
Checkout the details in this blog post, try it yourself and let us know what you think:
developers.google.com/privacy-

2024-05-18
Well this is moving quickly! You can now spin up FedCM on your own website and log in to https://webmention.io thanks to this open source project from Sam Goto! This is so much better than having to type out your website or even email address when logging in! Full instructions here:

https://github.com/fedidcg/FedCM/issues/240#issuecomment-2118606184
2024-05-16

Just did a test, and I think we may be able to implement FedCM in Mastodon. It seems that you can actually create Doorkeeper Applications with a client_id that's a URL, rather than having it generate a unique client_id for you.

However, where it fails is that you don't get a unique client_id, so registering the same client again fails with a duplicate record error (maybe this is intentional?)

I guess FedCM client_id's don't have a client_secret at all to use…

#Mastodon #MastoDev #FedCM

2024-05-12
This weekend I built a prototype of using FedCM for IndieAuth! This gets rid of the need to enter your domain when logging in to websites using IndieAuth! Demo video and notes here: https://aaronparecki.com/2024/05/12/3/fedcm-for-indieauth
Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2024-04-18

#FedCM is a new #browser API that enables #identity #federation without relying on third-party #cookies. With an upcoming new feature called Button Mode API, FedCM will be able to display a modal dialog and let the user sign in to the identity provider before signing into the relying party.
You can start experimenting with this new API from #Chrome 125 which is currently in beta and see how effectively it works. Learn more about this new API at developers.google.com/privacy-

Just finished a #FedCM 101 session at the OAuth Security Workshop with Sam Goto. So many great discussions and questions!

Slides available at tcslides.link/OSW24-FedCM101

#osw #oauthsecurityworkshop

Tim Cappalli in front of and pointing to a projector screen during the presentation
Eiji Kitamura / えーじ :verified:agektmr@infosec.exchange
2024-03-06

From Chrome 123, you can use the Domain Hints alongside the Federated Credential Management API (FedCM). With the Domain Hint API, developers can provide a better user experience by only showing the federated login accounts from the domain that they accept.
buff.ly/3wFmzTD

#FedCM is an emerging browser API that allows identity federation without relying on third-party cookies. Learn more about FedCM from here: buff.ly/3wEkHe2

#authentication #openid #oauth

DAASI InternationalDAASI_International
2023-02-28

This week our own David Hübner travelled to the US as an advocate for the German research community to join a hackathon, and discuss the future of and their meaning for , and with browser vendors like @chrome

For more info on check out fedidcg.github.io/FedCM/

Patrick Neppernepper
2022-11-18

Alright, time for a .

My name is Patrick. I work in at - more specifically on - you may have seen some of the products I get to work on with our globally distributed teams: .

I moved over to as many of you frustrated by its new, toxic leadership.

Outside of work, I'm a of three, as a local politician and councilman, and

Jeffrey Yasskinjyasskin@toot.cafe
2022-11-02

It would be really nice if opening a mastodon.wrongserver.social link would automatically open the toot in the Mastodon PWA I've installed. I think you'd need a central coordination domain to do it with 3p cookies, and those are going away anyway. @sgoto, can #FedCm do it? Could protocol handlers, maybe, if we expect the installed server to register mastodon: or activitypub: or something?

#WebStandards

Eiji Kitamuraagektmr@toot.cafe
2022-06-21

どうせブラウザだけで扱ってRPには渡されることのない情報なら、アカウントリストエンドポイントにはUID返して、トークンエンドポイントはPPID返せばいいのでは。
#openid #technight #fedcm

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst