Front channel and back channel

Two routes for federation and OAuth messages: the front channel passes through the user's browser, while the back channel runs directly between servers without the user in the path.

Federation and delegated authorisation protocols move messages between an identity or authorisation server and an application in two ways. NIST SP 800-63C-4 section 4.11 describes the back channel as a direct connection between the relying party and the identity provider that does not involve the subscriber, and the front channel as a route through a third party using redirects that involve the subscriber’s browser or device. What the front channel carries can be seen, logged or altered on the user’s device. The back channel is a server-to-server call in which each side can authenticate the other.

Protocols are built around the difference. In the OAuth 2.0 authorisation code grant (RFC 6749), a short-lived code travels through the browser, and the client exchanges it for tokens directly with the authorisation server, authenticating itself if it is a confidential client; PKCE protects the code while it is exposed. The SAML Web SSO profile commonly posts the SAML assertion through the browser, while the artifact binding sends only a reference that the service provider redeems over the back channel.

Exam relevance: questions in this area tend to ask why a flow passes a code through the browser rather than the token itself. Candidates are expected to treat the front channel as exposed and the back channel as the place for secrets and tokens.