> ## Content Index
> Fetch the complete content index at: https://www.chrismessina.me/llms.txt
> Use this file to discover other available public pages before exploring further.

# Feature request: OAuth in WordPress
- URL: https://www.chrismessina.me/blog/feature-request-oauth-in-wordpress/
- Published: 2008-07-02T17:52:40.000Z
- Updated: 2026-03-25T03:40:59.000Z
- Author: Chris Messina
- Tags: api, authorization, Citizen-centric Web, oauth, Open source, Technology, Web building, WordPress, xml-rpc

[](http://www.flickr.com/photos/factoryjoe/2629762893/?ref=chrismessina.me)In the past couple days, there's been a bit of a [dust-up](http://dougal.gunters.org/blog/2008/06/30/update-on-wordpress-blog-apis?ref=chrismessina.me) about some [changes](http://trac.wordpress.org/ticket/7157?ref=chrismessina.me) coming to WordPress in 2.6 -- namely [disabling ATOM and XML-RPC APIs by default](http://comox.textdrive.com/pipermail/wp-xmlrpc/2008-June/000231.html?ref=chrismessina.me). The [argument](http://joseph.randomnetworks.com/archives/2008/06/21/wordpress-26-to-have-xml-rpc-atompub-disabled-by-default/?ref=chrismessina.me) is that this will [make WordPress more secure out of the box](http://westi.wordpress.com/2008/06/20/making-the-default-install-more-secure/?ref=chrismessina.me) \-- but the question is [at what cost](http://www.red-sweater.com/blog/512/wordpress-to-disable-remote-access?ref=chrismessina.me)? And, is there a better solution to this problem rather than disabling features and functionality (even if only a small subset of users *currently* make use of these APIs) if the changes end up being [short-sighted](http://groups.google.com/group/wp-hackers/msg/f74432c58ebf03f9?ref=chrismessina.me)? This [topic](http://comox.textdrive.com/pipermail/wp-xmlrpc/2008-June/thread.html?ref=chrismessina.me#208) hit the [wp-xmlrpc mailing list](http://lists.automattic.com/mailman/listinfo/wp-xmlrpc?ref=chrismessina.me) where the conversation quickly devolved into spattering about SSL and other security related topics. [Allan Odgaard](http://wiki.macromates.com/Profiles/AllanOdgaard?ref=chrismessina.me) (creator [TextMate](http://macromates.com/?ref=chrismessina.me), as far as I can tell!) even proposed [inventing another authorization protocol](http://comox.textdrive.com/pipermail/wp-xmlrpc/2008-June/000222.html?ref=chrismessina.me). Sigh. There are a number of reasons why WordPress should adopt [OAuth](http://oauth.net/?ref=chrismessina.me) \-- and not just because we're going to require it for [DiSo](http://diso-project.org/?ref=chrismessina.me). Heck, [Stephen Paul Weber](http://singpolyma.net/?ref=chrismessina.me) already got [OAuth + AtomPub working for WordPress](http://singpolyma.net/2008/05/atompub-oauth-for-wordpress/?ref=chrismessina.me), and has completed a basic [OAuth plugin for WordPress](http://singpolyma.net/plugins/oauth/?ref=chrismessina.me). The pieces are nearly in place, not to mention the fact that OAuth will pretty much be essential if WordPress is going to adopt OpenID at some point down the road. It's also going to be quite useful if folks want to post from, say, a Google Gadget or OpenSocial application (or similar) to a WordPress blog if the XML-RPC APIs are going to be off by default (given [Google's wholesale embrace of OAuth](http://blog.oauth.net/2008/06/30/oauth-at-the-center-of-googles-open-web-technologies/?ref=chrismessina.me)). Now, fortunately, folks within Automattic are [supportive of OAuth](http://twitter.com/photomatt/statuses/848088633?ref=chrismessina.me), including Matt and Lloyd. There are plenty of benefits to going down this path, not to mention the ability to scope third party applications to certain permissions -- like letting Facebook see your private posts but not edit or create new ones -- or authorizing desktop applications to post new entries or upload photos or videos without having to remember your username and password (instead you'd type in your blog address -- and it would discover the authorization endpoints using [XRDS-Simple](http://xrds-simple.net/?ref=chrismessina.me) \-- [Eran](http://www.hueniverse.com/?ref=chrismessina.me) has more on [discovery](http://www.hueniverse.com/hueniverse/2008/06/explaining-disc.html?ref=chrismessina.me): [Magic](http://www.hueniverse.com/hueniverse/2008/07/beginners-guide.html?ref=chrismessina.me), [People vs. Machines](http://www.hueniverse.com/hueniverse/2008/07/beginners-gui-1.html?ref=chrismessina.me#more)). Anyway, WordPress and OAuth are natural complements, and with popular support and momentum behind the protocol, it's [tragic](http://www.readwriteweb.com/archives/lastfm%5Flaunches%5Fapi%5F20.php?ref=chrismessina.me) to see [needless](http://protocol7.com/archives/2008/06/29/lastfm-does-rest-api-fail/?ref=chrismessina.me) [reinvention](http://www.last.fm/api/authspec?ref=chrismessina.me) when so many modern applications [have the same problem of delegated authorization](http://groups.google.com/group/diso-project/browse%5Fthread/thread/609d1e1bfc2aca25/6215189b0ad655b4??ref=chrismessina.me#6215189b0ad655b4). I see this is a tremendous opportunity for both WordPress and OAuth and am looking forward to discussing this opportunity -- at least consideration for WordPress 2.7 -- and [tonight's meetup](http://upcoming.yahoo.com/event/854418/?ref=chrismessina.me) \-- for which I'm now late! Doh!

---

### 💬 Comments from the original post

**[Steve Ivy](http://redmonk.net/?ref=chrismessina.me)** · 2008-07-02 18:44:37

"The pieces are nearly in place, not to mention the fact that OAuth will pretty much be essential if WordPress is going to adopt OpenID at some point down the road." What does this mean, Chris? I mean, there's already OpenID for WP...

**[Joseph Scott](http://joseph.randomnetworks.com/?ref=chrismessina.me)** · 2008-07-02 22:15:13

I still need to beef up on some of the OAuth nuts and bolts, but from what I've seen, you can put me in the camp of people at Automattic interested in seeing OAuth in WordPress 2.7.

**[Chris Messina](http://factorycity.net/?ref=chrismessina.me)** · 2008-07-03 12:33:03

@Steve: I'm talking about WordPress.com accepting OpenID signins -- not WordPress.org, although in order to API usage, .org will also need OAuth. @Joseph -- didn't realize you were at Automattic...! Great news then! ;)