Black Buffalo · OAuth Scopes
Black Buffalo OAuth Scopes
OAuth 2.0
probed
Black Buffalo publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Black Buffalo API on a user’s behalf.
Tokens are issued from https://shopify.com/authentication/22588521/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyConsumer Packaged GoodsNicotine PouchesSmokeless Tobacco AlternativeEcommerceDirect to ConsumerRetailAgentic CommerceShopifyGraphQLModel Context ProtocolUniversal Commerce Protocol
Scopes: 4
Flows: authorizationCode
Method: probed
OAuth endpoints
Authorization URL
https://shopify.com/authentication/22588521/oauth/authorize
https://shopify.com/authentication/22588521/oauth/authorize
Token URL
https://shopify.com/authentication/22588521/oauth/token
https://shopify.com/authentication/22588521/oauth/token
Flows
authorizationCode
authorizationCode
Scopes (4)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OpenID Connect scope — issues an ID token identifying the shopper. | authorizationCode |
| Releases the email and email_verified claims for the authenticated shopper. | authorizationCode | |
| customer-account-api:full | Full access to the Shopify Customer Account API on behalf of the signed-in shopper — orders, addresses and profile for that customer. This is the scope that governs the order history the anonymous Storefront GraphQL schema deliberately does not expose. | authorizationCode |
| customer-account-mcp-api:full | Full access to the Customer Account MCP API — the authenticated, per-shopper MCP surface, distinct from the two anonymous MCP servers at /api/mcp and /api/ucp/mcp. | authorizationCode |
📄 Provider scope reference: https://shopify.dev/docs/api/customer