When to use CIBA
CIBA is not suitable when the same device both initiates and completes
authentication. For that case, use the standard authorization code flow.
Modes
Poll mode
The client polls the token endpoint periodically until the user approves or denies on their authentication device.Ping mode
The AS notifies the client when the user has approved, instead of the client polling. The client registers aclient_notification_endpoint.
The AuthenticationDevice interface
Implement this interface to deliver the out-of-band authentication request to
the user’s device:
Configuration
Endpoints
POST /oauth/bc-authorize
Initiates a backchannel authentication request. Only mounted when CIBAConfig is set.
Response (200 OK):
POST /oauth/token
Redeems an auth_req_id for an access token via the CIBA grant, dispatched
through the same token endpoint as every other grant type.
Returns
authorization_pending (slow down if hitting the interval) or the
standard token response on approval.
Error responses
See also
- JWT-Bearer client auth
- PAR + JAR
- Configuration reference
- RFC 9509: OAuth 2.0 Client-Initiated Backchannel Authentication