When to use each grant type

Use the appropriate OAuth 2.0 grant type based on the authentication requirements of the target API.
Table 1. Grant type recommendations
Scenario Recommended grant type
Calling a third-party API where no user context is needed, such as data synchronization or webhook delivery. Client Credentials
Calling an API that requires actions to be attributed to a specific service account. Resource Owner Password Credentials (ROPC)
The external API supports only Client Credentials. Client Credentials
The external API requires a username and password but does not support an interactive login flow. Resource Owner Password Credentials (ROPC)