Medusa · OAuth Scopes
Medusa OAuth Scopes
OAuth 2.0
probed
Medusa uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
E-CommerceHeadless CommerceOpen-SourceCommerceStorefrontOrder ManagementNode.jsGraphQLAgentic CommerceMCP
Scopes: 0
Flows:
Method: probed
Scopes (0)
Medusa implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.
There is no per-tool or per-resource scope. Access to the MCP server is all-or-nothing on a Medusa Cloud account, so an agent cannot be granted the documentation-search tool without also being granted the feedback-submission tool.
There is no per-tool or per-resource scope. Access to the MCP server is all-or-nothing on a Medusa Cloud account, so an agent cannot be granted the documentation-search tool without also being granted the feedback-submission tool.
📄 Provider scope reference: https://docs.medusajs.com/learn/introduction/build-with-llms-ai/mcp-server
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.