Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 322 Next »

This Work Group operates under the Kantara IPR Policy - Option Patent & Copyright: Reciprocal Royalty Free with Opt-Out to Reasonable And Non discriminatory (RAND) (HTML version). You can find any opt-outs on this page.

Home | Intro | Join | List | Archive (Mailman) | Archive (Google) | Calendar

The UMA V2.0 specifications are in draft!

The UMA V2.0 specifications are in draft! Our 2016 roadmap work has borne fruit! Check out the latest drafts as of 7 March 2017: UMA Core V2.0 revision 18 and OAuth Resource Registration V2.0 revision 06. Here is a detailed swimlane diagram that dynamically tracks the drafts. If you're interested to contribute to the imminent finalization of these specs, we welcome you! See the Join link up top. Click the image to view the UMA Movie, which premiered at the 23rd Internet Identity Workshop in October 2016.

User-Managed Access (UMA) is an award-winning OAuth-based protocol designed to give a web user a unified control point for authorizing who and what can get access to their online personal data, content, and services, no matter where all those things live on the web. Read the spec, join the group, check out the implementations, follow us on Twitter, like us on Facebook, get involved!

See the UMA Roadmap for 2016 page to see the use cases and technical issues that the Work Group is currently focusing on.

The short link for this page is



  • March 3: The UMA Legal subgroup is meeting again to look at important new deliverables. If you've got a legal specialty, or want to contribute to the connection between consent/permission/authorization/delegation and the regulatory data protection world, you're just the kind of person we're looking for.
  • January 19: Our 2016 roadmap work has borne fruit and the UMA V2.0 specifications are shaping up! See the latest spec links in the box above. If you're interested to contribute to the finalization of these specs, we welcome you! See the Join link up top.
  • November 4: The UMA Legal subgroup has a new sharpened-up charter today! Check out the Legal page for links to interim deliverables. Particularly if you're a "legal eagle", are familiar with GDPR, or have business use cases involving delegation or proxies/guardians, we'd love for you to join us and help out. (See the Join link on this page.)
  • March 29: One of UMA's three trust elevation methods, claims gathering, was reported on January 27 to be affected by a session fixation attack. The WG has produced an extension specification to enable mitigation of the attack called UMA Claims-Gathering Extension for Enhanced Security, and a background document to further discuss the attack, the mitigation chosen, and other approaches considered and possible. Many thanks to the original reporters of the issue and the group for its quick action.
  • Chair: Eve Maler
  • Vice-Chair: Maciej Machulak
  • Full leadership team list
  • Read about Kantara leadership roles
Teleconference Info





  • No labels