# Gymshark

**Canonical:** https://apis.io/providers/gymshark/  
**Website:** https://www.gymshark.com/  
**APIs profiled:** 1

Gymshark is a British fitness apparel and accessories brand founded in 2012 in Birmingham, England, selling gym and workout clothing direct to consumers worldwide through gymshark.com, a set of regional storefronts (uk., eu., row., de., fr., ca., au. and others) and its Gymshark Shop and Gymshark Training mobile apps. The storefront runs on Shopify behind a headless Next.js/OpenNext front end deployed on AWS, and customer identity is handled by an Auth0 tenant Gymshark operates on its own domain at auth.gymshark.com. Gymshark publishes no public developer portal, no developer documentation and no public product API; the only publicly discoverable machine-readable contract on its own hosts is the OpenID Connect / OAuth 2.0 authorization-server metadata served from auth.gymshark.com. Its engineering team does publish open-source Go, JavaScript and Swift libraries under the github.com/gymshark organization, and it runs a public vulnerability disclosure program on HackerOne.

## Kin Score — 21.4 / 100 (emerging)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 21.4).

| Facet | Score |
|---|---|
| Discoverability | 87.0 |
| Contract Quality | 0.0 |
| Governance | 3.1 |
| Operational Transparency | 15.8 |
| Developer Ergonomics | 17.4 |
| Commercial Clarity | 34.2 |

## Agent readiness — 9.0 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (1)

- **Gymshark Identity (OpenID Connect)** — The OpenID Connect / OAuth 2.0 authorization server Gymshark operates on its own domain at auth.gymshark.com (an Auth0 tenant) for Gymshark customer accounts across the web stor...

## Security (3)

- **Gymshark Authentication** — openIdConnect/oauth2 · 2 schemes
- **Gymshark Domain Security** — TLSv1.3 · DMARC
- **Gymshark Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Tags

Company, Retail, E-Commerce, Apparel, Fitness, Consumer, Direct To Consumer, Identity, OpenID Connect

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/gymshark/). Scores are computed from the provider's own public artifacts under a published rubric.
