CandyClub

CandyClub is a premium candy and confectionery brand founded in 2015, best known for its direct-to-consumer candy subscription boxes and its wholesale program that supplies curated specialty candies to boutique shops, hotels, resorts, and national retailers. The candyclub.com storefront runs on Shopify and is agent-commerce ready: it publishes an llms.txt agent guide, Shopify Customer Account OpenID Connect authentication, and a Universal Commerce Protocol (UCP) MCP endpoint that lets AI shopping agents search the catalog, build carts, apply discounts, and complete buyer-approved checkouts. CandyClub was added to the API Evangelist network as a 500 Global portfolio company; this profile is enriched from its public storefront, well-known discovery documents, and UCP/agent surface.

CandyClub publishes 1 API on the APIs.io network. Tagged areas include Company, Candy, Confectionery, Ecommerce, and Subscription.

CandyClub’s developer surface includes authentication and 10 more developer resources.

20.0/100 emerging ▬ flat Agent 25/100 agent aware Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
1 APIs 1 MCP Servers
CompanyCandyConfectioneryEcommerceSubscriptionRetailShopifyAgent CommerceUCP

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 20.0/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 3.9 / 20
Commercial Clarity 6.8 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 25/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/candyclub: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

CandyClub Agent Commerce (UCP)

Agent-facing commerce surface for the CandyClub Shopify storefront: a Universal Commerce Protocol (UCP) MCP endpoint plus read-only storefront browsing, governed by an llms.txt ...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

candyclub-mcp.yml

MCP SERVER

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Candyclub Authentication

openIdConnect/oauth2 · 1 scheme

SECURITY

Candyclub Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Candyclub Scopes

4 scopes · authorizationCode

4 scopes

SCOPES

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Access & Security 3

Authentication, authorization, and security posture

Commercial 2

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: candyclub
name: CandyClub
description: 'CandyClub is a premium candy and confectionery brand founded in 2015, best known for its direct-to-consumer
  candy subscription boxes and its wholesale program that supplies curated specialty candies to boutique shops, hotels, resorts,
  and national retailers. The candyclub.com storefront runs on Shopify and is agent-commerce ready: it publishes an llms.txt
  agent guide, Shopify Customer Account OpenID Connect authentication, and a Universal Commerce Protocol (UCP) MCP endpoint
  that lets AI shopping agents search the catalog, build carts, apply discounts, and complete buyer-approved checkouts. CandyClub
  was added to the API Evangelist network as a 500 Global portfolio company; this profile is enriched from its public storefront,
  well-known discovery documents, and UCP/agent surface.'
url: https://raw.githubusercontent.com/api-evangelist/candyclub/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://candyclub.com/cdn/shop/files/cc_logo.webp?v=1767705737&width=300
x-type: company
x-source: vc-portfolio
x-backed-by:
- 500-global
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-18'
tags:
- Company
- Candy
- Confectionery
- Ecommerce
- Subscription
- Retail
- Shopify
- Agent Commerce
- UCP
apis:
- name: CandyClub Agent Commerce (UCP)
  description: 'Agent-facing commerce surface for the CandyClub Shopify storefront: a Universal Commerce Protocol (UCP) MCP
    endpoint plus read-only storefront browsing, governed by an llms.txt agent guide and Shopify Customer Account OIDC. Checkout
    requires explicit buyer approval.'
  humanURL: https://candyclub.com/llms.txt
  baseURL: https://candyclub.com/api/ucp/mcp
  properties:
  - type: LLMsTxt
    url: llms/candyclub-llms.txt
  - type: MCPServer
    url: mcp/candyclub-mcp.yml
  - type: Authentication
    url: authentication/candyclub-authentication.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://candyclub.com
- type: LLMsTxt
  url: llms/candyclub-llms.txt
- type: MCPServer
  url: mcp/candyclub-mcp.yml
- type: WellKnown
  url: well-known/candyclub-well-known.yml
- type: Authentication
  url: authentication/candyclub-authentication.yml
- type: OAuthScopes
  url: scopes/candyclub-scopes.yml
- type: Conventions
  url: conventions/candyclub-conventions.yml
- type: DomainSecurity
  url: security/candyclub-domain-security.yml
- type: Login
  url: https://account.candyclub.com/authentication/oauth/authorize
- type: TermsOfService
  url: https://candyclub.com/policies/terms-of-service
- type: PrivacyPolicy
  url: https://candyclub.com/policies/privacy-policy
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence