BulletProof · OAuth Scopes

BulletProof OAuth Scopes

OAuth 2.0 probed

BulletProof publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the BulletProof API on a user’s behalf.

Tokens are issued from https://account.bulletproof.com/authentication/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyConsumer Packaged GoodsFood and BeverageHealth and WellnessSupplementsEcommerceDirect to ConsumerRetailAgentic CommerceShopify
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://account.bulletproof.com/authentication/oauth/authorize
Token URL
https://account.bulletproof.com/authentication/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid Standard OpenID Connect scope; requests an ID token for the signed-in customer. authorizationCode
email Releases the customer's email address and email_verified claim. authorizationCode
customer-account-api:full Full access to the customer account API for the signed-in customer — profile, addresses, orders and subscriptions. authorizationCode
customer-account-mcp-api:full Full access to the customer account MCP API — the agent-facing projection of the same customer account data. Notable as an explicitly agent-scoped grant. authorizationCode

Source

OAuth Scopes

bulletproof-scopes.yml Raw ↑
generated: '2026-08-08'
method: probed
source: https://shop.bulletproof.com/.well-known/openid-configuration
note: >-
  Scopes come from the live OAuth 2.0 / OpenID Connect discovery documents served on
  the Bulletproof hosts (identical payload at shop., account. and the myshopify origin).
  Bulletproof publishes no scope reference page of its own — these four are the complete
  scopes_supported list as advertised, nothing has been added.
issuer: https://shopify.com/authentication/434700319
schemes:
- name: customer-accounts
  type: openIdConnect
  source: https://shop.bulletproof.com/.well-known/openid-configuration
  flows:
  - flow: authorizationCode
    authorizationUrl: https://account.bulletproof.com/authentication/oauth/authorize
    tokenUrl: https://account.bulletproof.com/authentication/oauth/token
    pkce: S256
scopes:
- scope: openid
  description: Standard OpenID Connect scope; requests an ID token for the signed-in customer.
  flows: [authorizationCode]
  sources: ['well-known/bulletproof-openid-configuration.json']
- scope: email
  description: Releases the customer's email address and email_verified claim.
  flows: [authorizationCode]
  sources: ['well-known/bulletproof-openid-configuration.json']
- scope: customer-account-api:full
  description: >-
    Full access to the customer account API for the signed-in customer — profile,
    addresses, orders and subscriptions.
  flows: [authorizationCode]
  sources: ['well-known/bulletproof-openid-configuration.json']
- scope: customer-account-mcp-api:full
  description: >-
    Full access to the customer account MCP API — the agent-facing projection of the
    same customer account data. Notable as an explicitly agent-scoped grant.
  flows: [authorizationCode]
  sources: ['well-known/bulletproof-openid-configuration.json']
claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified]
gaps:
- >-
  The UCP MCP endpoint at /api/ucp/mcp requires a JWT for order and checkout tools but
  does not advertise which of these scopes mints it; the error body points at
  shopify.dev rather than a Bulletproof-owned page.