---
title: "Fail Backchannel Authentication Request"
method: POST
path: "/api/{serviceId}/backchannel/authentication/fail"
tags: ["CIBA"]
---

# Fail Backchannel Authentication Request

`POST /api/{serviceId}/backchannel/authentication/fail`

The API prepares JSON that contains an error. The JSON should be used as the response body of the
response which is returned to the client from the [backchannel authentication endpoint](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1\_0.html#auth\_backchannel\_endpoint).
### Description
This API is supposed to be called from within the implementation of the [backchannel authentication
endpoint](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1\_0.html#auth\_backchannel\_endpoint)
of the service in order to generate an error response to the client application.
The response from `/backchannel/authentication/fails` API has some parameters. Among them, it is
`action` parameter that the authorization server implementation should check first because it denotes
the next action that the authorization server implementation should take. According to the value
of `action`, the authorization server implementation must take the steps described below.
**INTERNAL\_SERVER\_ERROR**
When the value of `action` is `INTERNAL\_SERVER\_ERROR`, it means that (1) the `reason` request parameter
of the API call was `SERVER\_ERROR`, (2) an error occurred on Authlete side, or (3) the request parameters
of the API call were wrong. In this case, the authorization server implementation should return
a "500 Internal Server Error" response to the client application. However, in most cases, commercial
implementations prefer to use other HTTP status code than 5xx.
**BAD\_REQUEST**
When the value of `action` is `BAD\_REQUEST`, the authorization server implementation should return a
"400 Bad Request" response to the client application.
**FORBIDDEN**
When the value of `action` is `FORBIDDEN`, it means that the `reason` request parameter of the API call
was `ACCESS\_DENIED`. In this case, the backchannel authentication endpoint of the authorization
server implementation should return a "403 Forbidden" response to the client application.

## Path parameters

- `serviceId` string, required

## Request body

- BackchannelAuthenticationFailRequest
  - `ticket` string, required — The ticket which should be deleted on a call of Authlete's `/backchannel/authentication/fail` API. This request parameter is not mandatory but optional. If this request parameter is given and the ticket belongs to the service, the specified ticket is deleted from the database. Giving this parameter is recommended to clean up the storage area for the service.
  - `reason` 'ACCESS_DENIED' | 'EXPIRED_LOGIN_HINT_TOKEN' | 'INVALID_BINDING_MESSAGE' | 'INVALID_TARGET' | 'INVALID_USER_CODE' | 'MISSING_USER_CODE' | 'SERVER_ERROR' | 'UNAUTHORIZED_CLIENT' | 'UNKNOWN_USER_ID', required — The reason of the failure of the backchannel authentication request. This request parameter is not mandatory but optional. However, giving this parameter is recommended. If omitted, `SERVER_ERROR` is used as a reason.
  - `errorDescription` string — The description of the error. This corresponds to the `error_description` property in the response to the client.
  - `errorUri` string — The URI of a document which describes the error in detail. If this optional request parameter is given, its value is used as the value of the `error_uri` property.

## Response `200`

- BackchannelAuthenticationFailResponse
  - `resultCode` string — The code which represents the result of the API call.
  - `resultMessage` string — A short message which explains the result of the API call.
  - `action` 'INTERNAL_SERVER_ERROR' | 'BAD_REQUEST' | 'FORBIDDEN' — The next action that the authorization server implementation should take.
  - `responseContent` string — The content that the authorization server implementation is to return to the client application. Its format varies depending on the value of `action` parameter.

## Other responses

- `400`
- `401`
- `403`
- `500`

---

[API](https://skmtc.dev/authlete/apis/authlete-api.md) · [All operations](https://skmtc.dev/authlete/apis/authlete-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/authlete/authlete-api/revisions/8a534bc68775/schema)
