Centric Brands · OAuth Scopes

Centric Brands OAuth Scopes

OAuth 2.0 probed

Centric Brands publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Centric Brands API on a user’s behalf.

Tokens are issued from https://shopify.com/authentication/1157103680/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

ApparelAccessoriesFootwearBeautyKidsLifestyleBrand ManagementLicensingEntertainment LicensingSports LicensingFashionConsumer ProductsFortune 1000Private Equity Owned
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://shopify.com/authentication/1157103680/oauth/authorize
Token URL
https://shopify.com/authentication/1157103680/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid OpenID Connect authentication; issue an ID token for the buyer. authorizationCode
email Access the buyer's email address claim. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the signed-in buyer (orders, addresses, profile) for that brand store. authorizationCode
customer-account-mcp-api:full Full access to the Customer Account MCP API surface, the authenticated counterpart to the anonymous UCP shopping tools. authorizationCode

Source

OAuth Scopes

centric-brands-scopes.yml Raw ↑
generated: '2026-08-13'
method: probed
source: https://www.hudsonjeans.com/.well-known/openid-configuration
docs: https://shopify.dev/docs/api/customer
notes: >-
  scopes_supported advertised by the authorization servers behind Centric
  Brands' owned-brand storefronts (Shopify Customer Accounts). Identical on all
  eight probed hosts, with a per-store issuer. There is no corporate Centric
  Brands OAuth server; these scopes govern buyer-delegated access to a single
  brand store, not company data.
schemes:
  - name: ShopifyCustomerAccountOIDC
    source: well-known/centric-brands-openid-configuration.json
    flows:
      - flow: authorizationCode
        authorizationUrl: https://shopify.com/authentication/1157103680/oauth/authorize
        tokenUrl: https://shopify.com/authentication/1157103680/oauth/token
scopes:
  - scope: openid
    description: OpenID Connect authentication; issue an ID token for the buyer.
    flows:
      - authorizationCode
    sources:
      - well-known/centric-brands-openid-configuration.json
  - scope: email
    description: Access the buyer's email address claim.
    flows:
      - authorizationCode
    sources:
      - well-known/centric-brands-openid-configuration.json
  - scope: customer-account-api:full
    description: >-
      Full access to the Shopify Customer Account API on behalf of the
      signed-in buyer (orders, addresses, profile) for that brand store.
    flows:
      - authorizationCode
    sources:
      - well-known/centric-brands-openid-configuration.json
  - scope: customer-account-mcp-api:full
    description: >-
      Full access to the Customer Account MCP API surface, the authenticated
      counterpart to the anonymous UCP shopping tools.
    flows:
      - authorizationCode
    sources:
      - well-known/centric-brands-openid-configuration.json