Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Section
Column
width70%

This Work Group operates under the Kantara IPR Policy - Option Patent & Copyright: Reciprocal Royalty Free with Opt-Out to Reasonable And Non discriminatory (RAND) (HTML version). You can find any opt-outs on this page.

Home | Intro | → Join ← | List | Archive (Mailman) | Archive (Google) | Calendar


Image Removed

The Work Group has completed the process of implementing edits to the specifications as a result of the Public Comment/IPR Review period, and have approved the edited specs as Draft Recommendations and forwarded them to the Kantara Leadership Council for next steps towards finalization as Recommendations. You can see a summary in our Disposition of Comments document. See UMA 2.0 Grant for OAuth 2.0 Authorization (UMA Grant rev 08) and Federated Authorization for UMA 2.0 (FedAuthz rev 08).

Resources to understand more about UMA are available and growing. Don't miss the slides and video from Authorization: Age of UMA, the Introducing UMA 2.0 session delivered by two UMA coauthors at the Chicago Cloud Identity Summit (and stay tuned for the video). The Release Notes are complete except for Disposition of Comments content. The UMA Implementer's Guide is nearly complete. Also see these UMA Grant and FedAuthz sequence diagrams. If you're interested to help, we invite you to join the group! Fill out the Group Participation Agreement form to get going.
Panel
borderColor#99cc00
bgColor#ffffff
borderWidth4pt
titleUMA Version 2.0 specs are approved by the WG as final Draft Recommendations!
extension efforts

Image Added

We are undertaking some important new work on an UMA "policy manager" extension, and more. You can check it out by reading our Meetings and Minutes, and if you're interested to contribute, be sure to click our Join link above! ⬆︎

Here are the UMA Grant (PDF, HTML for deep linking) and UMA Federated Authorization Recommendations (PDF, HTML for deep linking). Don't miss the UMA2 masterclass delivered by two UMAnitarians at the Identiverse conference in Boston in June 2018 (slides and video). (The slides and video from the previous year's Authorization: Age of UMA session set in the Marvel Cinematic Universe was also a big hit!) The Release Notes review all final UMA1-to-UMA2 changes. See also the UMA Implementer's Guide, our list of known Implementations, and discussions of Case Studies. Finally, see the detailed UMA Grant sequence diagram and FedAuthz sequence diagram.

Panel
borderColor#7f7f7f
borderWidth0

Image RemovedImage Added

User-Managed Access (UMA) is an award-winning OAuth-based protocol designed to give an individual a unified control point for authorizing who and what can get access to their digital data, content, and services, no matter where all those things live. Read the specs, join the group, check out the implementations, follow us on Twitter, like us on Facebook, get involved!

The UMA Roadmap for 2016 page guided the use cases and technical issues that the Work Group focused on in its group is currently working on extensions to UMA V2.0 effort. You can find other drivers in the Work Group's original compendium of Scenarios and Use Cases, its Case Studies page, and its User Stories page.

The short link for this page is http://tinyurl.com/umawg.


News:

  • September 25: At the recent Consumer Identity World, Work Group chair Eve Maler presented on GDPR, PSD2, CIAM, and the Role of User-Managed Access (2.0). You can find the materials here.
  • September 11: The Work Group has completed the process of implementing edits to the specifications as a result of the Public Comment/IPR Review period, and have approved the edited specs as Draft Recommendations and forwarded them to the Kantara Leadership Council for next steps towards finalization as Recommendations. You can see a summary in our Disposition of Comments document. See UMA 2.0 Grant for OAuth 2.0 Authorization(UMA Grant rev 08) and Federated Authorization for UMA 2.0(FedAuthz rev 08).
  • July 27: The UMA V2.0 Public Comment period is closed! The Work Group is sorting through the comments we received, and determining and implementing responses as appropriate. You can follow along in our Disposition of Comments document-in-progress. We have published an interim set of resulting specifications: UMA 2.0 Grant for OAuth 2.0 Authorization (UMA Grant rev 06) and Federated Authorization for UMA 2.0 (FedAuthz rev 06).
  • July 24: Don't miss the slides from Authorization: Age of UMA, the Introducing UMA 2.0 session delivered by two UMA coauthors at the Chicago Cloud Identity Summit (and stay tuned for the video).
  • June 29: The Work Group has re-elected its leadership team: Eve Maler (@xmlgrrl) as chair, Maciej Machulak (@mmachulak) as vice-chair and implementations coordinator, and Domenico Catalano (@domcat) as graphics and user experience editor. Thanks to all for serving!
  • June 26: Don't miss this great new article on UMA 2.0 by spec coauthor Justin Richer.
  • May 25: The Work Group is pleased to announce that it has published the UMA Version 2.0 Draft Recommendations, approved for their Public Comment period: UMA 2.0 Grant for OAuth 2.0 Authorization (UMA Grant rev 05) and Federated Authorization for UMA 2.0 (FedAuthz rev 05). To comment, please email your comments to staff@kantarainitiative.org with the subject "UMAWG COMMENT SUBMISSION". For details about this period, see the Kantara announcement.
  • March 3: The UMA Legal subgroup is meeting again to look at important new deliverables. If you've got a legal specialty, or want to contribute to the connection between consent/permission/authorization/delegation and the regulatory data protection world, you're just the kind of person we're looking for.
  • November 4: The UMA Legal subgroup has a new sharpened-up charter today! Check out the Legal page for links to interim deliverables. Particularly if you're a "legal eagle", are familiar with GDPR, or have business use cases involving delegation or proxies/guardians, we'd love for you to join us and help out. (See the Join link on this page.)10 Jun '21: Congratulations to the new leadership team members! Alec Laws (of Identos) is the Chair and Steve Venema (of ForgeRock) is the Vice-Chair. The WG extends its thanks to former Chair Eve Maler for her previous service as chair. Information about the entire leadership team is here.
  • 20 Apr '21: You can get the latest and greatest UMA 101 presentation delivered by UMAnitarians Eve and George at IIW here.
  • 3 Dec '20: The UMA Work Group is pleased to accept a new profile contribution (to be provided immently) related to UK Pensions Dashboards as shown on-screen at its meeting today. Read all about it on our updated Third-Party Profiles and Extensions page.
  • 15 Oct '20: We are undertaking some important new work on an UMA "policy manager" extension, and more. You can check it out by reading our Meetings and Minutes, and if you're interested to contribute, be sure to click our Join link above! ⬆︎
  • 1 Oct '20: WG chair Eve Maler presented UMA to the Decentralized Identity Foundation Secure Data Storage WG. Here are her slides
  • 22 Nov '19: There's a new implementation up on the Implementations page: PatientShare from Lush Group. It's also an implementation of the HEART profiles. Read all about it and check it out!
Column
Column
width5%
 

Widget Connector
url
Column
width25%
Leadership
  • Chair: Eve MalerAlec Laws
  • Vice-Chair: Maciej MachulakSteve Venema
  • Full leadership team list
  • Read about Kantara leadership roles
Teleconference Info
Section
twitter
settings/widgets/419665047808274433
Column
width5%