This was in part caused by the general public’s comfort with federated identity for OAuth. If everyone already has one anyway (the thinking may go), why not mandate it?