Initiate a CIBA backchannel authentication request. The user receives a push notification to approve on their mobile device; poll POST /oauth/token with grant_type urn:openid:params:grant-type:ciba to retrieve the approval token.
EdDSA-signed JWT obtained via OAuth 2.1 client_credentials or CIBA