Part of: Agentic AILast updated 18 September 2026 · 1 min read

What is Client-Initiated Backchannel Authentication (CIBA)?

CIBA is an OpenID Connect flow that lets an authorization happen on a separate device or channel from the one making the request, such as approving an action on a phone while an agent or service completes it elsewhere. It supports agentic scenarios where the AI agent itself has no browser or user interface to redirect the customer through.

Frequently asked questions

Why would an agent need CIBA instead of a normal redirect-based OAuth flow?

Many agents have no browser or UI of their own to redirect a customer through, so CIBA lets the approval happen on a separate device, like the customer's phone, while the agent completes the request elsewhere.

Is CIBA specific to agentic identity?

No, it predates the current wave of AI agents and was originally built for call-center and IoT-style scenarios, but it fits naturally into agentic flows for the same reason.

Building the integration, not choosing it?Definitions stop where implementation starts. The developer docs carry the API references, SDKs and SCIM endpoints.
Developer doc

Ready to move beyond legacy CIAM?

Definitions are the easy part. Go live in weeks with identity that governs AI agents, customers, and partners from one place.

Learn more