ICON Aircraft OAuth Scopes
ICON Aircraft publishes 4 OAuth 2.0 scopes via the authorization_code, refresh_token, and urn:ietf:params:oauth:grant-type:jwt-bearer flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the ICON Aircraft API on a user’s behalf.
Tokens are issued from https://shopify.com/authentication/376732/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
OAuth endpoints
https://shopify.com/authentication/376732/oauth/authorize
https://shopify.com/authentication/376732/oauth/token
authorization_coderefresh_tokenurn:ietf:params:oauth:grant-type:jwt-bearer
Scopes (4)
| Scope | Description | Flows |
|---|---|---|
| openid | Standard OpenID Connect scope requesting an ID token for the signed-in shopper. | |
| Releases the shopper's email address as an OIDC claim. | ||
| customer-account-api:full | Full access to the Shopify Customer Account API for the authenticated shopper — their own orders, addresses and payment methods on the Shop ICON store. | |
| customer-account-mcp-api:full | Full access to the Shopify customer-account MCP API for the authenticated shopper. This is the scope an agent would present on buyer-scoped UCP tools such as get_order; tools/list and the catalog tools do not require it. |
📄 Provider scope reference: https://store.iconaircraft.com/.well-known/oauth-authorization-server
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.