Some OpenSocial containers use xoauth_security_token for signing requests, instead of oauth_token and oauth_token_secret.

Is XOauth an alternative to OAuth?(*) Who is behind XOauth and where is the official spec?

Casual Googling only lead me to xoauth.py from google-mail-xoauth-tools project which just states it's a "utilities for XOAUTH authentication".

(*)Aside: it mustn't be, because the container uses other oauth_xxx parameters alongside the xoauth_xxx ones.

Edit
Report