BulletProof

Bulletproof (Bulletproof 360, Inc.) is a Seattle-founded functional nutrition and health-and-wellness brand — toxin-tested coffee, C8 MCT oil, collagen, creamers and supplements — founded in 2013 by Dave Asprey and sold direct-to-consumer and through national retail. Bulletproof is not a software vendor and publishes no developer program, yet its commerce and content stacks expose a real, callable, unauthenticated machine surface: a Shopify Storefront GraphQL API that answers introspection anonymously at shop.bulletproof.com, a live UCP (Universal Commerce Protocol) MCP endpoint whose tools/list returns 13 agent tools with full JSON Schema input contracts, OAuth 2.0 / OpenID Connect discovery documents for customer accounts, agent-facing llms.txt and agents.md instructions on the storefront, and a 384-route WordPress REST API behind the editorial site.

BulletProof publishes 4 APIs on the APIs.io network. Tagged areas include Company, Consumer Packaged Goods, Food and Beverage, Health and Wellness, and Supplements.

BulletProof’s developer surface includes documentation, engineering blog, support, signup flow, authentication, and 17 more developer resources.

36.4/100 thin ▬ flat Agent 34/100 agent ready Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
4 APIs 1 MCP Servers
CompanyConsumer Packaged GoodsFood and BeverageHealth and WellnessSupplementsEcommerceDirect to ConsumerRetailAgentic CommerceShopify

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 36.4/100 · thin
Contract Quality 9.2 / 21
Developer Ergonomics 4.7 / 17
Commercial Clarity 5.8 / 17
Operational Transparency 0.6 / 11
Governance 0.3 / 10
Discoverability 7.9 / 9
Regulatory Posture 7.9 / 15
Agent readiness — 34/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 9 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Health regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/bulletproof: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 4

Individual APIs this provider publishes, each with its own machine-readable definition.

Bulletproof Storefront GraphQL API

The Shopify Storefront GraphQL API served from the Bulletproof store host. Anonymous introspection succeeded on 2026-08-08 (424 types, QueryRoot + Mutation), and anonymous queri...

Bulletproof UCP Agentic Commerce MCP

A live Model Context Protocol endpoint implementing the Universal Commerce Protocol (UCP) for agent-driven commerce. An anonymous tools/list returned 13 tools with complete JSON...

Bulletproof Storefront JSON Catalog

The unauthenticated Shopify storefront JSON catalog endpoints (/products.json, /collections.json, /products/{handle}.json, /collections/{handle}/products.json) documented in the...

Bulletproof WordPress Content REST API

The WordPress REST API behind the Bulletproof editorial site (bulletproof.com), self-describing 16 namespaces and 384 routes at /wp-json/ with no authentication schemes advertis...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Examples 3

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Bulletproof Authentication

none/oauth2/openIdConnect/bearer · 6 schemes

SECURITY

Bulletproof Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Bulletproof Scopes

4 scopes · authorizationCode

4 scopes

SCOPES

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: bulletproof
name: BulletProof
description: 'Bulletproof (Bulletproof 360, Inc.) is a Seattle-founded functional nutrition and health-and-wellness brand
  — toxin-tested coffee, C8 MCT oil, collagen, creamers and supplements — founded in 2013 by Dave Asprey and sold direct-to-consumer
  and through national retail. Bulletproof is not a software vendor and publishes no developer program, yet its commerce and
  content stacks expose a real, callable, unauthenticated machine surface: a Shopify Storefront GraphQL API that answers introspection
  anonymously at shop.bulletproof.com, a live UCP (Universal Commerce Protocol) MCP endpoint whose tools/list returns 13 agent
  tools with full JSON Schema input contracts, OAuth 2.0 / OpenID Connect discovery documents for customer accounts, agent-facing
  llms.txt and agents.md instructions on the storefront, and a 384-route WordPress REST API behind the editorial site.'
url: https://raw.githubusercontent.com/api-evangelist/bulletproof/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: profiled
x-tier-reason: enrichment-2026-08-08
image: https://cdn.shopify.com/s/files/1/0004/3470/0319/files/bp-logo-large.png?v=1785948157
specificationVersion: '0.20'
created: '2026-08-08'
modified: '2026-08-08'
tags:
- Company
- Consumer Packaged Goods
- Food and Beverage
- Health and Wellness
- Supplements
- Ecommerce
- Direct to Consumer
- Retail
- Agentic Commerce
- Shopify
apis:
- name: Bulletproof Storefront GraphQL API
  description: The Shopify Storefront GraphQL API served from the Bulletproof store host. Anonymous introspection succeeded
    on 2026-08-08 (424 types, QueryRoot + Mutation), and anonymous queries against shop, products, collections and cart return
    live data. Date-versioned (2024-10 through 2026-01 plus unstable all answered 200) with cost/complexity reported per request.
  humanURL: https://shop.bulletproof.com/agents.md
  baseURL: https://shop.bulletproof.com/api/2026-01/graphql.json
  tags:
  - GraphQL
  - Ecommerce
  - Storefront
  properties:
  - type: GraphQL
    url: graphql/bulletproof-storefront.graphql
  - type: Examples
    url: examples/bulletproof-storefront-graphql-response.json
  - type: DataModel
    url: data-model/bulletproof-data-model.yml
- name: Bulletproof UCP Agentic Commerce MCP
  description: A live Model Context Protocol endpoint implementing the Universal Commerce Protocol (UCP) for agent-driven
    commerce. An anonymous tools/list returned 13 tools with complete JSON Schema input contracts covering catalog search/lookup,
    product detail, cart, checkout and order. initialize reports serverInfo universal-commerce 0.1.0 on MCP protocol 2024-11-05.
    Tool calls require a resolvable UCP agent profile URI, and order/checkout tools additionally require a JWT.
  humanURL: https://shop.bulletproof.com/agents.md
  baseURL: https://shop.bulletproof.com/api/ucp/mcp
  tags:
  - MCP
  - Agentic Commerce
  - UCP
  properties:
  - type: MCPServer
    url: mcp/bulletproof-mcp.yml
  - type: ToolCrosswalk
    url: mcp/bulletproof-tool-crosswalk.yml
  - type: Examples
    url: examples/bulletproof-ucp-mcp-initialize.json
- name: Bulletproof Storefront JSON Catalog
  description: The unauthenticated Shopify storefront JSON catalog endpoints (/products.json, /collections.json, /products/{handle}.json,
    /collections/{handle}/products.json) documented in the store's own agents.md as the read-only browsing surface for agents
    that do not need to transact.
  humanURL: https://shop.bulletproof.com/agents.md
  baseURL: https://shop.bulletproof.com
  tags:
  - Ecommerce
  - Catalog
  - JSON
  properties:
  - type: Examples
    url: examples/bulletproof-storefront-products-json.json
- name: Bulletproof WordPress Content REST API
  description: The WordPress REST API behind the Bulletproof editorial site (bulletproof.com), self-describing 16 namespaces
    and 384 routes at /wp-json/ with no authentication schemes advertised. Covers posts, pages, recipes, reviewers and taxonomies
    used across the coffee, supplement, diet and recipe article libraries.
  humanURL: https://www.bulletproof.com/
  baseURL: https://www.bulletproof.com/wp-json/wp/v2
  tags:
  - Content
  - REST
  - WordPress
  properties:
  - type: Discovery
    url: https://www.bulletproof.com/wp-json/
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.bulletproof.com/
- type: SecondaryMarket
  url: https://forgeglobal.com/bulletproof_stock/
- type: Documentation
  url: https://shop.bulletproof.com/agents.md
- type: GitHubOrganization
  url: https://github.com/bulletproof360
- type: Blog
  url: https://www.bulletproof.com/blog/
- type: BlogRSS
  url: https://www.bulletproof.com/feed/
- type: Support
  url: https://shop.bulletproof.com/pages/contact-us
- type: SignUp
  url: https://shop.bulletproof.com/account/login
- type: TermsOfService
  url: https://shop.bulletproof.com/policies/terms-of-service
- type: PrivacyPolicy
  url: https://shop.bulletproof.com/policies/privacy-policy
- type: LLMsTxt
  url: llms/bulletproof-llms.txt
- type: WellKnown
  url: well-known/bulletproof-well-known.yml
- type: Authentication
  url: authentication/bulletproof-authentication.yml
- type: OAuthScopes
  url: scopes/bulletproof-scopes.yml
- type: Conventions
  url: conventions/bulletproof-conventions.yml
- type: Idempotency
  url: conventions/bulletproof-conventions.yml
- type: ErrorCatalog
  url: errors/bulletproof-problem-types.yml
- type: DeclineCodes
  url: errors/bulletproof-decline-codes.yml
- type: Lifecycle
  url: lifecycle/bulletproof-lifecycle.yml
- type: Conformance
  url: conformance/bulletproof-conformance.yml
- type: AgentSkill
  url: skills/_index.yml
- type: DomainSecurity
  url: security/bulletproof-domain-security.yml
x-enrichment:
  date: '2026-08-08'
  status: enriched
  artifacts_added: 27
  pass: local-v1