Bespoken Spirits · OAuth Scopes

Bespoken Spirits OAuth Scopes

OAuth 2.0 probed

Bespoken Spirits publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Bespoken Spirits API on a user’s behalf.

Tokens are issued from https://shopify.com/authentication/75681399024/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanySpiritsBeverage AlcoholEcommerceAgentic CommerceUniversal Commerce ProtocolModel Context ProtocolShopifyRetailManufacturing
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://shopify.com/authentication/75681399024/oauth/authorize
Token URL
https://shopify.com/authentication/75681399024/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid Standard OIDC scope requesting an ID token for the authenticated buyer. authorizationCode
email Release the buyer's email address and email_verified claim. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the authenticated buyer — orders, addresses, profile and subscriptions for this store. authorizationCode
customer-account-mcp-api:full Full access to the Shopify Customer Account MCP API — the authenticated, buyer-scoped counterpart to the anonymous storefront MCP endpoints catalogued in mcp/bespoken-spirits-mcp.yml. authorizationCode

Source

OAuth Scopes

bespoken-spirits-scopes.yml Raw ↑
generated: '2026-08-07'
method: probed
source: https://bespokenspirits.com/.well-known/openid-configuration
notes: >-
  These are the OAuth 2.0 / OIDC scopes advertised by the Shopify Customer Account
  authorization server bound to the bespokenspirits.com storefront. They are read
  verbatim from scopes_supported in the store's own /.well-known/openid-configuration
  and /.well-known/oauth-authorization-server documents. Bespoken Spirits publishes no
  scope reference page of its own; the descriptions below are the standard meanings of
  the scope names, not provider-authored copy.
schemes:
- name: shopify-customer-account-oidc
  source: well-known/bespoken-spirits-openid-configuration.json
  issuer: https://shopify.com/authentication/75681399024
  flows:
  - flow: authorizationCode
    authorizationUrl: https://shopify.com/authentication/75681399024/oauth/authorize
    tokenUrl: https://shopify.com/authentication/75681399024/oauth/token
    pkce: S256
scopes:
- scope: openid
  description: Standard OIDC scope requesting an ID token for the authenticated buyer.
  flows:
  - authorizationCode
  sources:
  - well-known/bespoken-spirits-openid-configuration.json
- scope: email
  description: Release the buyer's email address and email_verified claim.
  flows:
  - authorizationCode
  sources:
  - well-known/bespoken-spirits-openid-configuration.json
- scope: customer-account-api:full
  description: Full access to the Shopify Customer Account API on behalf of the
    authenticated buyer — orders, addresses, profile and subscriptions for this store.
  flows:
  - authorizationCode
  sources:
  - well-known/bespoken-spirits-openid-configuration.json
- scope: customer-account-mcp-api:full
  description: Full access to the Shopify Customer Account MCP API — the authenticated,
    buyer-scoped counterpart to the anonymous storefront MCP endpoints catalogued in
    mcp/bespoken-spirits-mcp.yml.
  flows:
  - authorizationCode
  sources:
  - well-known/bespoken-spirits-openid-configuration.json
x-evidence:
  fetched: '2026-08-07'
  probes:
  - url: https://bespokenspirits.com/.well-known/openid-configuration
    http_status: 200
  - url: https://bespokenspirits.com/.well-known/oauth-authorization-server
    http_status: 200