It's the worst delegated authorisation system except for all the others that have been tried from time to time.
The original OpenID was fine.
IndieAuth is fine (but I’ve yet to see an implementation out in the wild).
Tailscale’s implementation of OIDC is nice: https://tailscale.com/docs/integrations/identity/custom-oidc
But all that only makes sense if you own a domain name.