Client-Initiated Backchannel Authentication (CIBA)
An OpenID flow where an app requests a user's approval, and the user approves on a separate device.
Client-Initiated Backchannel Authentication is an OpenID Foundation specification for a decoupled flow in which a client application asks an OpenID provider to authenticate a user, and the user approves on a separate authentication device, such as a banking app, without a browser redirect. The client receives the result by polling, by notification or by push. It fits agents well, because an agent running in the background can request a person's approval for a specific step and wait for it.
Agent Minute explains this term on 20 December 2026.
Related terms
Human oversightMeasures that let people understand, monitor and, when needed, override or stop a high-risk AI system.Strong customer authenticationAuthentication using two or more independent elements from knowledge, possession and inherence.OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.FAPI 2.0 Security ProfileAn OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.