makeup.land · OAuth Scopes

makeup.land OAuth Scopes

OAuth 2.0 searched

makeup.land publishes 5 OAuth 2.0 scopes. Scopes are the fine-grained permissions an application requests at authorization time to act against the makeup.land API on a user’s behalf.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CosmeticsBeautyRetailE-CommerceShoppingLoyaltyGift CardsProduct SearchAgentic CommerceMCPAgent-NativeIsraelA2A
Scopes: 5 Flows: Method: searched

Scopes (5)

ScopeDescriptionFlows
full Full read + write access. Default scope for first-party tokens.
register Issue new customer registrations and read registrations belonging to the token's registration_source. Restricted to the /register and /registrations endpoints (plus customer opportunities).
giftcards Redeem gift cards. Required only by POST /gift-cards/redeem. The public /gift-cards/validate endpoint requires no token.
proposals Submit catalog enrichment proposals to /proposals. Read-only against the rest of the catalog.
read_only Marker for tokens whose read_only=true flag rejects every write with 403 read_only_token. Not negotiated at request time — set at token issuance.

Source

OAuth Scopes

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/makeup-land-openapi.yml
docs: https://makeup.land/auth.md
note: >-
  These are NOT OAuth 2.0 scopes negotiated at request time. derive-oauth-scopes.py found no oauth2 scheme
  (correctly). The provider publishes the same five scope names in three places — the OpenAPI root x-scopes
  map and per-operation security[] requirements on the bearerAuth scheme, the RFC 8414 authorization-server
  metadata scopes_supported, and the RFC 9728 protected-resource metadata scopes_supported — and auth.md
  explains they are fixed on a bearer token when a human issues it. read_only is a flag, not a scope, but
  the provider lists it under scopes_supported.
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: ml_<hex24>
  source: openapi/makeup-land-openapi.yml
  issuance: Manual, by email (info@makeup.land / shop@makeup.land) — auth.md "identity_assertion + email"
  discovery:
  - https://makeup.land/.well-known/oauth-authorization-server
  - https://makeup.land/.well-known/oauth-protected-resource
scopes:
- scope: full
  description: Full read + write access. Default scope for first-party tokens.
  operations: [listBrands, listProducts, getCustomer, upsertCustomer, patchCustomerTags, listCustomerOpportunities, getCustomerBestDeals, getCart, clearCart, addCartItem, patchCartItem, deleteCartItem, listOrders, listGiftCards, redeemGiftCard, listPaymentLinks, registerCustomer, listRegistrations, getRegistration, submitProposals]
  sources:
  - "openapi x-scopes"
  - "openapi security[]"
  - "oauth-authorization-server"
  - "oauth-protected-resource"
- scope: register
  description: Issue new customer registrations and read registrations belonging to the token's registration_source. Restricted to the /register and /registrations endpoints (plus customer opportunities).
  operations: [registerCustomer, listRegistrations, getRegistration, listCustomerOpportunities]
  sources:
  - "openapi x-scopes"
  - "openapi security[]"
  - "oauth-authorization-server"
  - "oauth-protected-resource"
- scope: giftcards
  description: Redeem gift cards. Required only by POST /gift-cards/redeem. The public /gift-cards/validate endpoint requires no token.
  operations: [redeemGiftCard]
  sources:
  - "openapi x-scopes"
  - "openapi security[]"
  - "oauth-authorization-server"
  - "oauth-protected-resource"
- scope: proposals
  description: Submit catalog enrichment proposals to /proposals. Read-only against the rest of the catalog.
  operations: [submitProposals]
  sources:
  - "openapi x-scopes"
  - "openapi security[]"
  - "oauth-authorization-server"
  - "oauth-protected-resource"
- scope: read_only
  kind: flag
  description: Marker for tokens whose read_only=true flag rejects every write with 403 read_only_token. Not negotiated at request time — set at token issuance.
  operations: []
  sources: [openapi x-scopes, oauth-authorization-server, oauth-protected-resource]
unauthenticated_operations:
- validateGiftCard
- listProducts (catalog filters only — bearer required once phone, include=inventory or relevant_to_phone is passed)
selector_not_scope:
  name: phoneIdentifier
  note: The phone query/body parameter selects a customer and is declared as an apiKey securityScheme, but the provider's own description says it is not a credential and bearerAuth is always required alongside it.

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/makeup-land-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.