CIBA is an OpenID Connect flow that lets an authorization happen on a separate device or channel from the one making the request, such as approving an action on a phone while an agent or service completes it elsewhere. It supports agentic scenarios where the AI agent itself has no browser or user interface to redirect the customer through.
Frequently asked questions
Why would an agent need CIBA instead of a normal redirect-based OAuth flow?
Many agents have no browser or UI of their own to redirect a customer through, so CIBA lets the approval happen on a separate device, like the customer's phone, while the agent completes the request elsewhere.
Is CIBA specific to agentic identity?
No, it predates the current wave of AI agents and was originally built for call-center and IoT-style scenarios, but it fits naturally into agentic flows for the same reason.
.avif)