On This Page
pilot
Choose Your Integration Method
Cybersource
offers three OAuth 2.0 integration methods. The method you
integrate to is determined by your organization type and how your client obtains consent
from another party to access their data. Grant Type | Integration Method | Description | Organization type | Example |
|---|---|---|---|---|
Authorization Code Grant | On-Behalf-Of | A merchant or user signs in to the Cybersource Business
Center and grants your client permission to act on their behalf.This
integration method is also known as on-behalf-of, or
OBO. | AI agent enabler | An AI assistant performs payment operations, dispute handling, or
reconciliation on behalf of a consenting merchant, limited to the
permissions that the merchant approves. |
Partner acquirer or partner reseller | A bank portal initiates refunds or views reporting data on behalf of
its merchants. | |||
Technology partner | A SaaS platform accesses payment and reporting APIs on behalf of its
merchants. | |||
Merchant | A merchant grants a trusted client permission to access account data
or perform permitted API operations on the merchant’s behalf. | |||
Authorization Code Grant | OpenID Connect (OIDC) | Your client authenticates users with one of the supported sign-in methods.
| Partner acquirer or partner reseller | A bank platform uses federated login with Cybersource
or coordinates sign-in across multiple merchants. |
Technology partner | A partner portal uses SSO so merchants can sign in with their
Cybersource credentials. | |||
Client Credentials Grant | Machine-to-Machine (M2M) | Your system accesses Cybersource APIs without user sign-in
or merchant consent during the flow.The client and Cybersource authenticate each other before Cybersource issues an access token. | AI agent enabler | An AI coding agent or automated process connects to VAP MCP to
perform reconciliation, reporting, or scheduled payment
operations. |
Merchant | A merchant ERP or reconciliation system accesses payment APIs
securely with OAuth tokens instead of static API keys. | |||
Partner acquirer or partner reseller | An enterprise reporting platform or AI automation system aggregates
data across multiple merchants. | |||
Technology partner | A Remote MCP integration or embedded component calls Cybersource APIs as a system client. |