Liquid Death · OAuth Scopes

Liquid Death OAuth Scopes

OAuth 2.0 probed

Liquid Death publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Liquid Death API on a user’s behalf.

Tokens are issued from https://account.liquiddeath.com/authentication/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyBeveragesConsumer Packaged GoodsDirect to ConsumerEcommerceRetailAgentic CommerceUniversal Commerce ProtocolMCPShopify
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://account.liquiddeath.com/authentication/oauth/authorize
Token URL
https://account.liquiddeath.com/authentication/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid Standard OpenID Connect scope; requests an ID token identifying the customer. authorizationCode
email Releases the customer's email address and email_verified claim. authorizationCode
customer-account-api:full Full access to the customer account API for this store on behalf of the signed-in customer (orders, addresses, subscriptions, profile). authorizationCode
customer-account-mcp-api:full Full access to the customer account surface over MCP — the agent-mediated equivalent of customer-account-api:full. Its presence is what makes customer-scoped agent operations (e.g. get_order) possible alongside the anonymous UCP shopping transport. authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-08-01'
method: probed
source: https://liquiddeath.com/.well-known/openid-configuration
summary:
  scheme_count: 1
  scope_count: 4
  note: >-
    Scopes are taken verbatim from the scopes_supported array of the store's own OIDC/OAuth discovery
    documents. Liquid Death publishes no separate scopes reference page; these four are the complete
    advertised set.
schemes:
  - name: customer-account-oidc
    type: openIdConnect
    issuer: https://shopify.com/authentication/7942897737
    source: well-known/liquid-death-openid-configuration.json
    flows:
      - flow: authorizationCode
        authorizationUrl: https://account.liquiddeath.com/authentication/oauth/authorize
        tokenUrl: https://account.liquiddeath.com/authentication/oauth/token
        pkce_required_methods: [S256]
scopes:
  - scope: openid
    description: Standard OpenID Connect scope; requests an ID token identifying the customer.
    flows: [authorizationCode]
    sources: [well-known/liquid-death-openid-configuration.json, well-known/liquid-death-oauth-authorization-server.json]
  - scope: email
    description: Releases the customer's email address and email_verified claim.
    flows: [authorizationCode]
    sources: [well-known/liquid-death-openid-configuration.json, well-known/liquid-death-oauth-authorization-server.json]
  - scope: 'customer-account-api:full'
    description: >-
      Full access to the customer account API for this store on behalf of the signed-in customer
      (orders, addresses, subscriptions, profile).
    flows: [authorizationCode]
    sources: [well-known/liquid-death-openid-configuration.json, well-known/liquid-death-oauth-authorization-server.json]
  - scope: 'customer-account-mcp-api:full'
    description: >-
      Full access to the customer account surface over MCP — the agent-mediated equivalent of
      customer-account-api:full. Its presence is what makes customer-scoped agent operations
      (e.g. get_order) possible alongside the anonymous UCP shopping transport.
    flows: [authorizationCode]
    sources: [well-known/liquid-death-openid-configuration.json, well-known/liquid-death-oauth-authorization-server.json]
gaps:
  - >-
    No granular read/write scope decomposition is offered — both non-OIDC scopes are ":full". An agent
    that only needs order status must request the same authority as one that can mutate the account.
x-evidence:
  fetched: '2026-08-01'
  url: https://liquiddeath.com/.well-known/openid-configuration
  http_status: 200