Dolls Kill · OAuth Scopes
Dolls Kill OAuth Scopes
OAuth 2.0
searched
Dolls Kill publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Dolls Kill API on a user’s behalf.
Tokens are issued from https://account.dollskill.com/authentication/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
CompanyRetailE-commerceFashionApparelCommerceShopifyAgentic CommerceUniversal Commerce ProtocolMCPGraphQLDirect to Consumer
Scopes: 4
Flows: authorizationCode
Method: searched
OAuth endpoints
Authorization URL
https://account.dollskill.com/authentication/oauth/authorize
https://account.dollskill.com/authentication/oauth/authorize
Token URL
https://account.dollskill.com/authentication/oauth/token
https://account.dollskill.com/authentication/oauth/token
Flows
authorizationCode
authorizationCode
Scopes (4)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OpenID Connect scope; requests an ID token identifying the signed-in customer. | authorizationCode |
| Access to the customer's email address and email_verified claim. | authorizationCode | |
| customer-account-api:full | Full access to the Shopify Customer Account API for the authenticated customer — orders, addresses, payment methods and profile. Observed in the live login redirect issued by account.dollskill.com, which requests openid+email+customer-account-api:full. | authorizationCode |
| customer-account-mcp-api:full | Full access to the Customer Account MCP API — the authenticated, customer-scoped counterpart to the anonymous UCP commerce MCP endpoint at /api/ucp/mcp. This is the scope an agent would need to read a buyer's own order history rather than only transact on the public catalog. | authorizationCode |
📄 Provider scope reference: https://www.dollskill.com/.well-known/oauth-authorization-server