My overall point I guess was that if I'm not off base about this, I think any OAuth library that can't request a scope is not really compliant. That's not an OpenID-specific thing. And where there's one bad bug, there are more, so I wouldn't likely trust that library to be viable, whatever it is. -- Scott