Quick Start
Last updated
Was this helpful?
CIBA (Client-Initiated Backchannel Authentication) onboarding is currently available only to Government agencies and is assessed on a case-by-case basis.
For a call-centre use case:
A call-centre agent verifies the caller’s identity
The agent initiates a CIBA request via Singpass
A push notification is sent to the user’s Singpass app
The user reviews and approves the request
The transaction proceeds upon successful authentication
Create a staging app via the Singpass Developer Portal (SDP): https://docs.developer.singpass.gov.sg/docs/singpass-developer-portal-sdp/user-guide/create-staging-app
Configuration:
Select openid as the only scope
Use dummy values for fields not applicable (e.g. Site URL, Redirect URL)
Configure your JWKS endpoint
Share the following details via Partner Support:
Description of your CIBA use case
When is CIBA triggered?
Why is CIBA required?
Expected monthly transaction volume
Systems that will integrate with Singpass
The Singpass Product and Security teams will assess:
Alignment with CIBA policy
Authentication assurance requirements
User journey and risk controls
Availability of fallback flows
We may follow up with clarifications during this stage.
If the use case is approved:
Your use case will be whitelisted
Your team can proceed with testing in staging
Once testing is complete:
Submit a Production App Request via SDP
Indicate that the app is for CIBA
Include your User Journey (UJ)
Singpass will whitelist your client ID for CIBA usage
Last updated
Was this helpful?
Was this helpful?