Glossary

What is CIBA?

CIBA is an authentication flow where the user approves a sign-in on a separate device. Its full name is Client-Initiated Backchannel Authentication. The application starts the request, and the user confirms it out of band.

What does CIBA do?

CIBA moves the user approval to a backchannel. The application does not redirect the browser. Instead, the identity provider (IdP) contacts the user on a trusted device. The user approves or denies the request there. CIBA is part of the OpenID Connect family.

How does the CIBA flow work?

The application sends a request to the identity provider (IdP). The identity provider (IdP) then prompts the user on a known device. The user reviews the request and approves it. The identity provider (IdP) returns tokens to the application.

Where do companies use CIBA?

CIBA suits flows without a browser on the same device. A call center agent can start a sign-in for a customer. The customer then approves it on a phone.

  • Call center identity checks
  • Point-of-sale approvals
  • Smart-device sign-in

How does SenseCrypt use CIBA?

SenseCrypt is a passwordless identity provider (IdP) from Seventh Sense. It supports CIBA, OIDC, and OAuth 2.0 with PKCE and PAR.

With CIBA, the user approves the sign-in by face login on a phone. The face match runs on-device, so SenseCrypt stores no biometric data on the server.

Frequently asked questions

What does CIBA stand for?

CIBA stands for Client-Initiated Backchannel Authentication. It is part of the OpenID Connect family.

How is CIBA different from an OIDC redirect?

An OIDC redirect uses the browser on one device. CIBA moves the approval to a separate, trusted device through a backchannel.

Does SenseCrypt support CIBA?

Yes. SenseCrypt supports CIBA. The user approves the sign-in by face login on a phone.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.