OAuth 2.0 client credentials flow for system-to-system (partner banks) - OAuth 2.0 authorization code flow for user-facing applications (portal, mobile) - Mutual TLS for batch transfer endpoint - JWT token validation steps (all five checks from Section 21.6)