Hacker News new | past | comments | ask | show | jobs | submit login

OAuth is a family of RFCs, including 6749, 6750, and others. While 6749 is the minimum for OAuth2, in the specific case of the three largest providers under discussion, many other extension specs have been implemented. The OpenID connect logout spec has become the de facto logout spec for OAuth (as the OAuth RFC makes no mention of logout). All three providers mentioned implement it as the primary logout mechanism on the web.

Spec: http://openid.net/specs/openid-connect-frontchannel-1_0.htm

Edit: I should say, this spec also doesn't require cookies - you can use HTML5 local storage or another mechanism. In practice however, if you log into a Google service like YouTube, or a Microsoft service like Outlook, or a Facebook third party like Spotify, they use cookies.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
