Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.

This Work Group operates under the Kantara IPR Policy - Option Patent & Copyright: Reciprocal Royalty Free with Opt-Out to Reasonable And Non discriminatory (RAND) (HTML version). You can find any opt-outs on this page.

Home | Intro | Join | List | Archive (Mailman) | Archive (Google) | Calendar

 Image Removed

The UMA V1.0.1 specifications are Kantara Recommendations! The UMA Core V1.0.1 Recommendation and the OAuth Resource Set Registration V1.0.1 Recommendation are now available (check out the Release Notes too). Many thanks to the Work Group, the Kantara staff, and the membership for their support
titleUMA V1.0.1 specifications approved by the Kantara membership
UMA2 has an active business-legal framework workstream

Image Added

The premise of the Work Group's report A Proposed Licensing Model for User-Managed Access is that UMA enables the individual to centrally manage access and use rights with respect to personal digital assets by converting permission tokens into machine-readable licenses. The group is working on a companion document that outlines a larger business-legal framework for achieving a wide variety of rights delegation use cases involving UMA technology.

Here are the UMA Grant (PDF, HTML for deep linking) and UMA Federated Authorization Recommendations (PDF, HTML for deep linking). Don't miss the UMA2 masterclass delivered by two UMAnitarians at the Identiverse conference in Boston in June 2018 (slides and video). (The slides and video from the previous year's Authorization: Age of UMA session set in the Marvel Cinematic Universe was also a big hit!) The Release Notes review all final UMA1-to-UMA2 changes. See also the UMA Implementer's Guide, our list of known Implementations, and discussions of Case Studies. Finally, see the detailed UMA Grant sequence diagram and FedAuthz sequence diagram.

Image Removed

Image Added

User-Managed Access (UMA) is an award-winning OAuth-based protocol designed to give

a web user

an individual a unified control point for authorizing who and what can get access to their

online personal

digital data, content, and services, no matter where all those things live

on the web

. Read the


specs, join the group, check out the implementations, follow us on Twitter, like us on Facebook, get involved!

See the UMA Roadmap for 2016 page to see the use cases and technical issues that the Work Group is currently focusing on.

The group is currently working on extensions to UMA V2.0.

The short link for this page is


Many thanks to the Work Group, the Kantara staff, and the membership for their support as we cleaned up various small bugs throughout the spring and summer and returned the specs to the community for review in the fall.


  • June 23: Today Eve Maler (@xmlgrrl), Maciej Machulak (@mmachulak), and Domenico Catalano (@domcat) were re-elected to their leadership team positions – chair, vice-chair, and user experience editor, respectively. Maciej was also elected to the new position of UMA Developer Resources Work Group liaison. See the Leadership Team page for all details. Thanks to all previously serving leadership team members for their service!
  • March 29: One of UMA's three trust elevation methods, claims gathering, was reported on January 27 to be affected by a session fixation attack. The WG has produced an extension specification to enable mitigation of the attack called UMA Claims-Gathering Extension for Enhanced Security, and a background document to further discuss the attack, the mitigation chosen, and other approaches considered and possible. Many thanks to the original reporters of the issue and the group for its quick action.
  • February 12: The new UMA Roadmap for 2016 page keeps track of the use cases we are prioritizing and currently focusing on.
  • January 25: Enabling user-managed access requires a "BLT sandwich" – not just technical solutions, but well-rounded business and legal solutions as well! A new set of UMA Legal auxiliary material is now available on this wiki, representing the work done by the WG and its ad hoc legal subgroup. Stay tuned for more news and deliverables.
  • January 17: As of December 23, the Kantara All-Member Ballot for the UMA V1.0.1 specifications passed with flying colors. The UMA Core V1.0.1 Recommendation and the OAuth Resource Set Registration V1.0.1 Recommendation are now available (check out the Release Notes too).
    • 16 Jul '20: Make sure to register for the new Kantara UMA webinar taking place on July 21st at 1pm ET – it will be all about health info interop and user control, and will include a demonstration.
    • 22 Nov '19: There's a new implementation up on the Implementations page: PatientShare from Lush Group. It's also an implementation of the HEART profiles. Read all about it and check it out!

    Widget Connector
    • Chair: Eve Maler
    • Vice-Chair: Maciej Machulak
    • Full leadership team list
    • Read about Kantara leadership roles
    Teleconference Info