Client Initiated Backchannel Authentication (CIBA) is an extension to OpenID Connect that improves the end-user experience during authentication and authorization in a federated environment.
Like OpenID Connect, CIBA is an authentication flow, governing how clients are identified and granted access. With CIBA, user consent can be requested through an out-of-band flow. For example, when making an online purchase, CIBA improves user experience because the customer’s browser will not have to redirect to a financial institution for authorization. Instead, the customer receives a push notification from the financial institution’s mobile app to complete authorization. This allows the customer to avoid confusing browser redirects.