A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?
The authorization code grant redirects each user to Cisco Webex to authenticate and consent, then returns a short-lived code the app exchanges for an access token and a refresh token. The refresh token enables long-term access without further user interaction, and each organization consents separately, matching the stated requirements.
Why this answer
Delegated access across many organizations requires each user to authenticate and consent at Cisco Webex, which the authorization code grant accomplishes. Exchanging the returned code yields both an access token and a refresh token, so the integration can renew access silently afterward. The other grants either lack refresh capability, require unsafe password handling, or represent the app rather than the user.
Exam trap
The trap here is choosing client credentials because it needs no user interaction, overlooking that it cannot represent delegated per-organization user consent.