Skip to content

Decoupled AuthZ Flows

Dave Tonge edited this page Jul 30, 2020 · 1 revision

In this flow the Client starts an AuthZ flow via a back channel endpoint and then asynchronously receives a notification from the AS when authorization is complete.

We have the Device Flow and also OpenID Connect CIBA that support these types of flows, but I'm interested in it being supported as a "first class" flow in the new protocol.

Use cases include:

  • User authorizing via a smart phone while at a public kiosk / terminal
  • User authorizing via laptop / smart phone while on a phone call to a customer service agent