Nice API != decentralized.
Nice API != decentralized.
The source for OpenPhoto is on Github (mobile and web clients). Anyone can install the software on any server they want. The user then connects their instance of OpenPhoto to their personal cloud account (think AWS or other).
There's no central repository or database. If you spin up an OpenPhoto instance then I'll never know about it personally unless you send me a link to it.
So the API is self contained as well. Your OpenPhoto instance has it's own API and is an OAuth provider. You can use the mobile app to point it to your host and it will take you through the OAuth flow requiring you to log in to your site. We determine the "owner" by email address as part of the setup flow.
OpenPhoto doesn't have the concept of "users". Any user can sign in (at the moment) with BrowserID which basically says that the user viewing owns a given email address. This allows anyone to sign in to any OpenPhoto site - without having an "OpenPhoto" account.
From there all permissions are based on email address. I can give any user access to any photo by their email address.
Not sure what you mean by giving Flickr permission to look at a photo. If you give an app permission to your photos that's done via OAuth and you can revoke that token at any time.