FILTER BY TAG
pilot

Choose Your Integration Method

Cybersource
offers three OAuth 2.0 integration methods. The method you integrate to is determined by your organization type and how your client obtains consent from another party to access their data.
OAuth 2.0 Integration Methods
Grant Type
Integration Method
Description
Organization type
Example
Authorization Code Grant
On-Behalf-Of
A merchant or user signs in to the
Cybersource
Business Center and grants your client permission to act on their behalf.
This integration method is also known as on-behalf-of, or OBO.
AI agent enabler
An AI assistant performs payment operations, dispute handling, or reconciliation on behalf of a consenting merchant, limited to the permissions that the merchant approves.
Partner acquirer or partner reseller
A bank portal initiates refunds or views reporting data on behalf of its merchants.
Technology partner
A SaaS platform accesses payment and reporting APIs on behalf of its merchants.
Merchant
A merchant grants a trusted client permission to access account data or perform permitted API operations on the merchant’s behalf.
Authorization Code Grant
OpenID Connect (OIDC)
Your client authenticates users with one of the supported sign-in methods.
  • Sign in through the
    Cybersource
    Business Center.
  • Single sign-on, or SSO.
  • A federated identity relationship between
    Cybersource
    and another platform.
Partner acquirer or partner reseller
A bank platform uses federated login with
Cybersource
or coordinates sign-in across multiple merchants.
Technology partner
A partner portal uses SSO so merchants can sign in with their
Cybersource
credentials.
Client Credentials Grant
Machine-to-Machine (M2M)
Your system accesses
Cybersource
APIs without user sign-in or merchant consent during the flow.
The client and
Cybersource
authenticate each other before
Cybersource
issues an access token.
AI agent enabler
An AI coding agent or automated process connects to VAP MCP to perform reconciliation, reporting, or scheduled payment operations.
Merchant
A merchant ERP or reconciliation system accesses payment APIs securely with OAuth tokens instead of static API keys.
Partner acquirer or partner reseller
An enterprise reporting platform or AI automation system aggregates data across multiple merchants.
Technology partner
A Remote MCP integration or embedded component calls
Cybersource
APIs as a system client.