---
name: cas-auto-debit
description: "Integrate Cas Auto Debit (scopes: auto_debit): integration steps, the APIs to call and the pre-production checklist."
---

# Cas — Auto Debit

> Source: https://cas.so/en/product/auto-debit · Markdown: https://cas.so/en/product/auto-debit.md

_This skill is generated from the Cas documentation. When you need details (schemas, error codes, examples), fetch the latest Markdown from the links below instead of guessing._

## When to use this skill

When integrating, extending or debugging Cas **Auto Debit** in your system.

## Product summary

Auto Debit is a service that automatically deducts an amount from your customer's account and
transfers it to your business account to automatically renew service plans, settle orders, collect recurring fees, and more.

## Scopes

`auto_debit`

## Integration flow

Below are the steps to integrate Auto Debit into your product.
1. Create a grant [/grant/token](https://cas.so/en/general/api/grant/create.md) with `scopes` set to `auto_debit`.

2. Open the Cas Link interface using the `grantToken` returned in the previous step. [See details](https://cas.so/en/general/link.md)

3. After the user completes authentication, your frontend will receive a `publicToken`. Use this `publicToken` to obtain an `accessToken` for the grant.

4. Once you have the `accessToken`, call the [Auto Debit account identity API](https://cas.so/en/general/api/auto-debit-identity.md) to verify the account information.

5. Call the [Auto Debit API](https://cas.so/en/general/api/auto-debit.md) to create an automatic debit order for renewing your customer's service plan, settling orders, and more.

6. When an Auto Debit transaction is processed successfully or fails,
the Cas system sends a [webhook](https://cas.so/en/general/api/webhook.md) with the details in the `autoDebit` field.
When your system receives this notification, it should re-verify the payment information and continue with the next steps.

## APIs used in this flow

- [Create grant token](https://cas.so/en/general/api/grant/create.md)
- [Auto Debit Identity](https://cas.so/en/general/api/auto-debit-identity.md)
- [Auto Debit](https://cas.so/en/general/api/auto-debit.md)
- [Webhook](https://cas.so/en/general/api/webhook.md)
- [Exchange public token for an access token](https://cas.so/en/general/api/grant/exchange.md)

## Read before writing code

- [Cas core](https://cas.so/en/skills/cas-core/SKILL.md)
- [Cas Link](https://cas.so/en/general/link.md)
- [Webhook](https://cas.so/en/general/api/webhook.md)
- [Errors](https://cas.so/en/errors.md)

## Rules you must follow when writing code

- `clientId` / `secretKey` live on the server in environment variables only — never ship them to a client, never commit them.
- Request only the `scopes` the product needs; extra scopes mean extra cost and risk.
- Avoid duplicate grants: check your database for a live grant before opening Cas Link again.
- Store `accessToken` and `grantId` encrypted and linked to your user; one user may hold several grants. Never surface these values in the UI.
- Log `requestId` (on every response) and `grantId` (on grant-related responses) for every call — this is what Cas support needs to trace an issue.
- Every API call needs a timeout and backoff retry for transient failures; never blindly retry money-moving calls (use your own idempotency key).
- Webhooks: accept them only from Cas IPs, return 2xx fast and process asynchronously, and make handling idempotent — deliveries can repeat or arrive out of order.
- Handle `GRANT_LOGIN_REQUIRED` by reopening Cas Link in Update mode instead of making the user relink from scratch.
- Handle `GRANT` webhooks: `USER_PERMISSION_REVOKED`, `GRANT_DELETED`, `GRANT_PAUSED`, `DEFAULT_UPDATE` — reflect the link state in your system.
- Call `/grant/remove` when a user unlinks in your app, and handle the OTP-verification branch.
- Run the whole flow on `https://sandbox.bankhub.dev` first; switch to `https://production.bankhub.dev` together with the production secrets.

## Before going to production

Verify against the **entire** production checklist: https://cas.so/en/launch-checklist.md

For every checklist item, point at the code (file path + line) that proves it is handled, or state why it does not apply. Never tick an item without evidence.

## Other Cas skills

Full catalogue (use it to add more Cas products later):

https://cas.so/en/skills/index.json
