releases.shpreview
Auth0/Auth0 Changelog/Client-Initiated Backchannel Authentication (CIBA) flow is now available in Early Access

Client-Initiated Backchannel Authentication (CIBA) flow is now available in Early Access

January 8, 2025Auth0 Changelog
$npx @buildinternet/releases show rel_7WIE_NRIffEISCbB98RW1

We are delighted to announce that support for the Client-Initiated Backchannel Authentication (CIBA) flow is now available in Early Access.

The CIBA flow works as a decoupled authentication flow across two different devices:

  • Consumption device: initiates the authentication request.
  • Authentication device: handles end-user authentication, implemented as a custom mobile app which embeds the Guardian mobile SDK.

The CIBA flow supports a number of powerful use cases driven by backend client applications, such as:

  • Customer authentication by headless devices or devices with limited interaction capabilities.
  • Customer authentication in call centre scenarios.
  • Authorising sensitive operations on behalf of yourself or a third-party e.g. a customer service agent.

To evaluate CIBA for securing your sensitive customer interactions, contact your Technical Account Manager. For more details, check out our product documentation.

Fetched April 23, 2026