When to use each grant type
Use the appropriate OAuth 2.0 grant type based on the authentication requirements of the target API.
| Scenario | Recommended grant type |
|---|---|
| Calling a third-party API where no user context is needed, such as data synchronization or webhook delivery. | Client Credentials |
| Calling an API that requires actions to be attributed to a specific service account. | Resource Owner Password Credentials (ROPC) |
| The external API supports only Client Credentials. | Client Credentials |
| The external API requires a username and password but does not support an interactive login flow. | Resource Owner Password Credentials (ROPC) |