Skip to main content
CIBA (Client-Initiated Backchannel Authentication, RFC 9509) decouples the consumption device from the authentication device. A user interacts with an authentication device (e.g., a phone app receiving a push notification) to approve a request initiated by a completely separate consumption device (e.g., a call center agent’s desktop, an IoT appliance, or a voice assistant speaker). No browser redirect is required.

When to use CIBA

CIBA is not suitable when the same device both initiates and completes authentication. For that case, use the standard authorization code flow.

Modes

Poll mode

The client polls the token endpoint periodically until the user approves or denies on their authentication device.

Ping mode

The AS notifies the client when the user has approved, instead of the client polling. The client registers a client_notification_endpoint.
Push mode (where the AS delivers the token directly to the client notification endpoint) is not supported in v2.4. Use Poll or Ping.

The AuthenticationDevice interface

Implement this interface to deliver the out-of-band authentication request to the user’s device:
A minimal push-notification implementation using Firebase Cloud Messaging:

Configuration

Endpoints

POST /oauth/bc-authorize

Initiates a backchannel authentication request. Only mounted when CIBAConfig is set. Response (200 OK):

POST /oauth/token

Redeems an auth_req_id for an access token via the CIBA grant, dispatched through the same token endpoint as every other grant type. Returns authorization_pending (slow down if hitting the interval) or the standard token response on approval.

Error responses

See also

Last modified on October 7, 2026