Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Section
Column
width70%

This Work Group operates under the Kantara IPR Policy - Option Patent & Copyright: Reciprocal Royalty Free with Opt-Out to Reasonable And Non discriminatory (RAND) (HTML version). You can find any opt-outs on this page.

Home | Intro | → Join ← | List | Archive (Mailman) | Archive (Google) | Calendar


Image Removed

The UMA V2.0 specifications are in draft! Check out the latest drafts: UMA Core V2.0 revision 12 and OAuth Resource Registration V2.0 revision 04. Here is a detailed swimlane diagram that tracks the drafts. If
Panel
borderColor#99cc00
bgColor#ffffff
borderWidth4pt
titleThe UMA V2.0 specifications are in draft!
UMA extension efforts

Image Added

We are undertaking some important new work on an UMA "policy manager" extension, and more. You can check it out by reading our Meetings and Minutes, and if you're interested to contribute, be sure to the finalization of these specs, we welcome you! See the Join link up topclick our Join link above! ⬆︎

Here are the UMA Grant (PDF, HTML for deep linking) and UMA Federated Authorization Recommendations (PDF, HTML for deep linking). Don't miss the UMA2 masterclass delivered by two UMAnitarians at the Identiverse conference in Boston in June 2018 (slides and video). (The slides and video from the previous year's Authorization: Age of UMA session set in the Marvel Cinematic Universe was also a big hit!) The Release Notes review all final UMA1-to-UMA2 changes. See also the UMA Implementer's Guide, our list of known Implementations, and discussions of Case Studies. Finally, see the detailed UMA Grant sequence diagram and FedAuthz sequence diagram.

Panel
borderColor#7f7f7f
borderWidth0
Image Removed

Image Added

User-Managed Access (UMA) is an award-winning OAuth-based protocol designed to give

a web user

an individual a unified control point for authorizing who and what can get access to their

online personal

digital data, content, and services, no matter where all those things live

on the web

. Read the

spec

specs, join the group, check out the implementations, follow us on Twitter,

like us on Facebook,

get involved!

See the UMA Roadmap for 2016 page to see the use cases and technical issues that the Work Group is currently focusing on.

The group is currently working on extensions to UMA V2.0.

The short link for this page is http://tinyurl.com/umawg.

 


News:

  • January 19: Our 2016 roadmap work has borne fruit and the UMA V2.0 specifications are shaping up! Check out the latest drafts: UMA Core V2.0 revision 12 and OAuth Resource Registration V2.0 revision 04. If you're interested to contribute to the finalization of these specs, we welcome you! See the Join link up top.
  • November 4: The UMA Legal subgroup has a new sharpened-up charter today! Check out the Legal page for links to interim deliverables. Particularly if you're a "legal eagle", are familiar with GDPR, or have business use cases involving delegation or proxies/guardians, we'd love for you to join us and help out. (See the Join link on this page.)
  • June 23: Today Eve Maler (@xmlgrrl), Maciej Machulak (@mmachulak), and Domenico Catalano (@domcat) were re-elected to their leadership team positions – chair, vice-chair, and user experience editor, respectively. Maciej was also elected to the new position of UMA Developer Resources Work Group liaison. See the Leadership Team page for all details. Thanks to all previously serving leadership team members for their service!
  • March 29: One of UMA's three trust elevation methods, claims gathering, was reported on January 27 to be affected by a session fixation attack. The WG has produced an extension specification to enable mitigation of the attack called UMA Claims-Gathering Extension for Enhanced Security, and a background document to further discuss the attack, the mitigation chosen, and other approaches considered and possible. Many thanks to the original reporters of the issue and the group for its quick action.
    • 10 Jun '21: Congratulations to the new leadership team members! Alec Laws (of Identos) is the Chair and Steve Venema (of ForgeRock) is the Vice-Chair. The WG extends its thanks to former Chair Eve Maler for her previous service as chair. Information about the entire leadership team is here.
    • 20 Apr '21: You can get the latest and greatest UMA 101 presentation delivered by UMAnitarians Eve and George at IIW here.
    • 3 Dec '20: The UMA Work Group is pleased to accept a new profile contribution (to be provided immently) related to UK Pensions Dashboards as shown on-screen at its meeting today. Read all about it on our updated Third-Party Profiles and Extensions page.
    • 15 Oct '20: We are undertaking some important new work on an UMA "policy manager" extension, and more. You can check it out by reading our Meetings and Minutes, and if you're interested to contribute, be sure to click our Join link above! ⬆︎
    • 1 Oct '20: WG chair Eve Maler presented UMA to the Decentralized Identity Foundation Secure Data Storage WG. Here are her slides
    • 22 Nov '19: There's a new implementation up on the Implementations page: PatientShare from Lush Group. It's also an implementation of the HEART profiles. Read all about it and check it out!
    Column
    Column
    width5%
     

    Widget Connector
    url
    Column
    width25%
    Leadership
    • Chair: Eve MalerAlec Laws
    • Vice-Chair: Maciej MachulakSteve Venema
    • Full leadership team list
    • Read about Kantara leadership roles
    Teleconference Info
    Section
    twitter
    settings/widgets/419665047808274433

     

    Column
    width5%