CandyClub · OAuth Scopes

CandyClub OAuth Scopes

OAuth 2.0 searched

CandyClub publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the CandyClub API on a user’s behalf.

Tokens are issued from https://account.candyclub.com/authentication/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyCandyConfectioneryEcommerceSubscriptionRetailShopifyAgent CommerceUCP
Scopes: 4 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://account.candyclub.com/authentication/oauth/authorize
Token URL
https://account.candyclub.com/authentication/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid OpenID Connect authentication; issues an ID token for the customer. authorizationCode
email Access to the customer's email address and email_verified claim. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the signed-in customer. authorizationCode
customer-account-mcp-api:full Full access to the Customer Account MCP API for agent-driven commerce (UCP shopping endpoint). authorizationCode

Source

OAuth Scopes

candyclub-scopes.yml Raw ↑
generated: '2026-07-18'
method: searched
source: https://candyclub.com/.well-known/openid-configuration
docs: https://candyclub.com/.well-known/openid-configuration
schemes:
  - name: ShopifyCustomerAccountOIDC
    source: well-known/candyclub-openid-configuration.json
    flows:
      - flow: authorizationCode
        authorizationUrl: https://account.candyclub.com/authentication/oauth/authorize
        tokenUrl: https://account.candyclub.com/authentication/oauth/token
scopes:
  - scope: openid
    description: OpenID Connect authentication; issues an ID token for the customer.
    flows: [authorizationCode]
    sources: [well-known/candyclub-openid-configuration.json]
  - scope: email
    description: Access to the customer's email address and email_verified claim.
    flows: [authorizationCode]
    sources: [well-known/candyclub-openid-configuration.json]
  - scope: customer-account-api:full
    description: Full access to the Shopify Customer Account API on behalf of the signed-in customer.
    flows: [authorizationCode]
    sources: [well-known/candyclub-openid-configuration.json]
  - scope: customer-account-mcp-api:full
    description: Full access to the Customer Account MCP API for agent-driven commerce (UCP shopping endpoint).
    flows: [authorizationCode]
    sources: [well-known/candyclub-openid-configuration.json]