---
term: "Client-Initiated Backchannel Authentication (CIBA)"
category: "Authentication and security"
url: https://agenticopenfinance.com/glossary/ciba
source: AgenticOpenFinance glossary
---

# Client-Initiated Backchannel Authentication (CIBA)

> An OpenID flow where an app requests a user's approval, and the user approves on a separate device.

Client-Initiated Backchannel Authentication is an OpenID Foundation specification for a decoupled flow in which a client application asks an OpenID provider to authenticate a user, and the user approves on a separate authentication device, such as a banking app, without a browser redirect. The client receives the result by polling, by notification or by push. It fits agents well, because an agent running in the background can request a person's approval for a specific step and wait for it.

Related terms: [Human oversight](https://agenticopenfinance.com/glossary/human-oversight.md), [Strong customer authentication](https://agenticopenfinance.com/glossary/strong-customer-authentication.md), [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md), [FAPI 2.0 Security Profile](https://agenticopenfinance.com/glossary/fapi-2.md)
