Mammoth Brands · OAuth Scopes

Mammoth Brands OAuth Scopes

OAuth 2.0 probed

Mammoth Brands publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Mammoth Brands API on a user’s behalf.

Tokens are issued from https://shopify.com/authentication/88395284786/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyConsumer Packaged GoodsRetailE-CommercePersonal CareAgentic CommerceModel Context ProtocolShopify
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://shopify.com/authentication/88395284786/oauth/authorize https://shopify.com/authentication/55874814054/oauth/authorize
Token URL
https://shopify.com/authentication/88395284786/oauth/token https://shopify.com/authentication/55874814054/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid Standard OpenID Connect scope; requests an ID token for the authenticated customer. authorizationCode
email Releases the customer's email address and email_verified claim. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the signed-in customer (orders, addresses, profile, subscriptions). authorizationCode
customer-account-mcp-api:full Full access to the customer-account MCP surface on behalf of the signed-in customer — the authenticated counterpart to the anonymous storefront MCP server at /api/mcp. authorizationCode

Source

OAuth Scopes

harry-s-scopes.yml Raw ↑
generated: '2026-07-31'
method: probed
source: https://harrys.com/.well-known/openid-configuration
note: >-
  Scopes come from the scopes_supported array of the live OIDC / RFC 8414 discovery documents
  the two Shopify-hosted brands serve from their own domains. There is no OpenAPI to derive
  from and Mammoth Brands publishes no scope reference page, so descriptions below are the
  standard OIDC meanings plus the Shopify Customer Account API scope names verbatim — nothing
  was invented and no scope was added that the discovery document does not list.
schemes:
- name: shopify-customer-account-oidc-harrys
  source: well-known/harry-s-harrys-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://shopify.com/authentication/88395284786/oauth/authorize
    tokenUrl: https://shopify.com/authentication/88395284786/oauth/token
    pkce: S256
- name: shopify-customer-account-oidc-flamingo
  source: well-known/harry-s-flamingo-openid-configuration.json
  flows:
  - flow: authorizationCode
    authorizationUrl: https://shopify.com/authentication/55874814054/oauth/authorize
    tokenUrl: https://shopify.com/authentication/55874814054/oauth/token
    pkce: S256
scopes:
- scope: openid
  description: Standard OpenID Connect scope; requests an ID token for the authenticated customer.
  flows: [authorizationCode]
  sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json]
- scope: email
  description: Releases the customer's email address and email_verified claim.
  flows: [authorizationCode]
  sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json]
- scope: customer-account-api:full
  description: Full access to the Shopify Customer Account API on behalf of the signed-in customer (orders, addresses, profile, subscriptions).
  flows: [authorizationCode]
  sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json]
- scope: customer-account-mcp-api:full
  description: >-
    Full access to the customer-account MCP surface on behalf of the signed-in customer — the
    authenticated counterpart to the anonymous storefront MCP server at /api/mcp.
  flows: [authorizationCode]
  sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json]
claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified]
docs: null
docs_note: Mammoth Brands publishes no developer documentation for these scopes; the discovery document is the only source.