Bombas · OAuth Scopes
Bombas OAuth Scopes
OAuth 2.0
probed
Bombas publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Bombas API on a user’s behalf.
Tokens are issued from https://shopify.com/authentication/11195850/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyRetailEcommerceApparelDirect to ConsumerCommerceAgentic CommerceUniversal Commerce ProtocolModel Context ProtocolShopify
Scopes: 4
Flows: authorizationCode
Method: probed
OAuth endpoints
Authorization URL
https://shopify.com/authentication/11195850/oauth/authorize
https://shopify.com/authentication/11195850/oauth/authorize
Token URL
https://shopify.com/authentication/11195850/oauth/token
https://shopify.com/authentication/11195850/oauth/token
Flows
authorizationCode
authorizationCode
Scopes (4)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OpenID Connect scope; requests an ID token identifying the signed-in Bombas customer. | authorizationCode |
| Releases the customer's email and email_verified claims. | authorizationCode | |
| customer-account-api:full | Full access to the Shopify Customer Account API for the signed-in customer (orders, addresses, profile, subscriptions). | authorizationCode |
| customer-account-mcp-api:full | Full access to the Shopify customer-account MCP API for the signed-in customer - the authenticated, customer-scoped MCP surface, distinct from the anonymous UCP shopping MCP endpoint. | authorizationCode |
📄 Provider scope reference: https://shop.bombas.com/.well-known/oauth-authorization-server