Out of band authorization (OOB)
Abbreviation: OOB
Pronunciation: OWT uhv BAND aw-thur-uh-ZAY-shun (O-O-B)
Also known as: Out of band authorization, OOB
Definition
Out of band authorization (OOB) is a security mechanism or control discipline that out-of-band authorization approves an action through a separate communication channel or device from the one that initiated the request. Out-of-band authorization adds an independent path for confirming login, payment, recovery, or administrative actions. Examples include approving on a registered mobile app, calling a verified contact, or using a separate hardware device. If both paths rely on the same compromised phone, email account, browser session, or support process, the second channel may provide little additional protection.
Overview
Out-of-band authorization adds an independent path for confirming login, payment, recovery, or administrative actions. Examples include approving on a registered mobile app, calling a verified contact, or using a separate hardware device.
Security depends on true channel independence. If both paths rely on the same compromised phone, email account, browser session, or support process, the second channel may provide little additional protection.
Strong implementations display transaction details, authenticate the approval device, prevent prompt fatigue, expire requests, and bind authorization to the exact action. Enrollment and channel replacement require equal protection against social engineering and account takeover. The confirmation message should make unauthorized denial and reporting easy.
An auditable record of Out of band authorization (OOB) should link checkout, authentication, authorization, capture, transfer, delivery, refund, dispute, and settlement events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.
The payment and commerce workflow for Out of band authorization (OOB) should locate where evidence enters, where a rule or judgment is applied, what state changes, and which downstream service relies on the result.
Out of band authorization (OOB) is a security mechanism or control discipline that out-of-band authorization approves an action through a separate communication channel or device from the one that initiated the request. OOB authorization helps only when the second path is independent, trusted, context-bound, and protected during enrollment, use, and recovery.
For Out of band authorization (OOB), the trust decision should establish Out of band authorization (OOB) is a security mechanism or control discipline that out-of-band authorization approves an action through a separate communication channel or device from the one that initiated and bind the result to the requested action and protected resource. Teams should test issuance, storage, validation, expiry, revocation, recovery, and privileged override for permissions and protected actions, rather than checking only a successful request. Logs concerning the Out of band permission decision and permissions and protected actions should support investigation without exposing reusable secrets or unnecessary personal data.
Key Takeaway
OOB authorization helps only when the second path is independent, trusted, context-bound, and protected during enrollment, use, and recovery.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)