pilot

Choose Your Integration Method {#oauth-intro-setup}
===================================================

`Cybersource` offers three OAuth 2.0 integration methods. The method you integrate to is determined by your organization type and how your client obtains consent from another party to access their data.

|        Grant Type        |    Integration Method    |                                                                                                                Description                                                                                                                |          Organization type           |                                                                                   Example                                                                                   |
|--------------------------|--------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Authorization Code Grant | On-Behalf-Of             | A merchant or user signs in to the `Cybersource` Business Center and grants your client permission to act on their behalf. This integration method is also known as on-behalf-of, or OBO.                                                 | AI agent enabler                     | An AI assistant performs payment operations, dispute handling, or reconciliation on behalf of a consenting merchant, limited to the permissions that the merchant approves. |
| Authorization Code Grant | On-Behalf-Of             | A merchant or user signs in to the `Cybersource` Business Center and grants your client permission to act on their behalf. This integration method is also known as on-behalf-of, or OBO.                                                 | Partner acquirer or partner reseller | A bank portal initiates refunds or views reporting data on behalf of its merchants.                                                                                         |
| Authorization Code Grant | On-Behalf-Of             | A merchant or user signs in to the `Cybersource` Business Center and grants your client permission to act on their behalf. This integration method is also known as on-behalf-of, or OBO.                                                 | Technology partner                   | A SaaS platform accesses payment and reporting APIs on behalf of its merchants.                                                                                             |
| Authorization Code Grant | On-Behalf-Of             | A merchant or user signs in to the `Cybersource` Business Center and grants your client permission to act on their behalf. This integration method is also known as on-behalf-of, or OBO.                                                 | Merchant                             | A merchant grants a trusted client permission to access account data or perform permitted API operations on the merchant's behalf.                                          |
| Authorization Code Grant | OpenID Connect (OIDC)    | Your client authenticates users with one of the supported sign-in methods. * Sign in through the `Cybersource` Business Center. * Single sign-on, or SSO. * A federated identity relationship between `Cybersource` and another platform. | Partner acquirer or partner reseller | A bank platform uses federated login with `Cybersource` or coordinates sign-in across multiple merchants.                                                                   |
| Authorization Code Grant | OpenID Connect (OIDC)    | Your client authenticates users with one of the supported sign-in methods. * Sign in through the `Cybersource` Business Center. * Single sign-on, or SSO. * A federated identity relationship between `Cybersource` and another platform. | Technology partner                   | A partner portal uses SSO so merchants can sign in with their `Cybersource` credentials.                                                                                    |
| Client Credentials Grant | Machine-to-Machine (M2M) | Your system accesses `Cybersource` APIs without user sign-in or merchant consent during the flow. The client and `Cybersource` authenticate each other before `Cybersource` issues an access token.                                       | AI agent enabler                     | An AI coding agent or automated process connects to VAP MCP to perform reconciliation, reporting, or scheduled payment operations.                                          |
| Client Credentials Grant | Machine-to-Machine (M2M) | Your system accesses `Cybersource` APIs without user sign-in or merchant consent during the flow. The client and `Cybersource` authenticate each other before `Cybersource` issues an access token.                                       | Merchant                             | A merchant ERP or reconciliation system accesses payment APIs securely with OAuth tokens instead of static API keys.                                                        |
| Client Credentials Grant | Machine-to-Machine (M2M) | Your system accesses `Cybersource` APIs without user sign-in or merchant consent during the flow. The client and `Cybersource` authenticate each other before `Cybersource` issues an access token.                                       | Partner acquirer or partner reseller | An enterprise reporting platform or AI automation system aggregates data across multiple merchants.                                                                         |
| Client Credentials Grant | Machine-to-Machine (M2M) | Your system accesses `Cybersource` APIs without user sign-in or merchant consent during the flow. The client and `Cybersource` authenticate each other before `Cybersource` issues an access token.                                       | Technology partner                   | A Remote MCP integration or embedded component calls `Cybersource` APIs as a system client.                                                                                 |
[OAuth 2.0 Integration Methods]

