Abcoffee · Authentication Profile

Abcoffee Authentication

Authentication

Abcoffee secures its APIs with oauth2, openIdConnect, and http across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyCoffeeFood and BeverageRetailCommerceAgentic CommerceMCPUniversal Commerce ProtocolShopifyIndiaSubscription
Methods: oauth2, openIdConnect, http Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

shopify-customer-account-oidc openIdConnect
shopify-agent-jwt http
scheme: bearer
ucp-agent-profile other

Source

Authentication Profile

abcoffee-authentication.yml Raw ↑
generated: '2026-09-05'
method: probed
source: >-
  https://abcoffee.in/.well-known/openid-configuration,
  https://abcoffee.in/.well-known/oauth-authorization-server,
  https://abcoffee.in/.well-known/oauth-protected-resource,
  live MCP probes of https://abcoffee.in/api/ucp/mcp
note: >-
  Derived from discovery documents fetched from abcoffee's own host, not from an OpenAPI - abcoffee
  publishes no OpenAPI. The authorization server is Shopify's Customer Account platform
  (issuer https://shopify.com/authentication/54968025206), which is the identity provider Shopify
  hosts for this store; the RFC 9728 protected-resource document served at abcoffee.in names
  abcoffee.in as the resource and that issuer as its authorization server.
summary:
  types: [oauth2, openIdConnect, http]
  api_key_in: []
  oauth2_flows: [authorizationCode]
  anonymous_surface: true
schemes:
- name: shopify-customer-account-oidc
  type: openIdConnect
  openIdConnectUrl: https://abcoffee.in/.well-known/openid-configuration
  issuer: https://shopify.com/authentication/54968025206
  authorizationUrl: https://shopify.com/authentication/54968025206/oauth/authorize
  tokenUrl: https://shopify.com/authentication/54968025206/oauth/token
  end_session_endpoint: https://shopify.com/authentication/54968025206/logout
  jwks_uri: https://shopify.com/authentication/54968025206/.well-known/jwks.json
  grant_types: [authorization_code, refresh_token, 'urn:ietf:params:oauth:grant-type:jwt-bearer']
  response_types: [code]
  pkce: [S256]
  id_token_signing_alg: [RS256]
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post]
  sources: [well-known/abcoffee-openid-configuration.json]
- name: shopify-agent-jwt
  type: http
  scheme: bearer
  bearerFormat: JWT
  applies_to:
  - 'mcp:get_order'
  evidence: >-
    A tools/call for get_order without a token returns JSON-RPC error -32000 "AuthenticationRequired"
    with HTTP 403 and the message "Unauthorized: A valid JWT is required to call get_order. See
    https://shopify.dev/docs/agents/get-started/authentication".
  docs: https://shopify.dev/docs/agents/get-started/authentication
  sources: ['probe: POST https://abcoffee.in/api/ucp/mcp tools/call get_order']
- name: ucp-agent-profile
  type: other
  description: >-
    Every MCP tool requires meta["ucp-agent"].profile - a URI pointing at the calling agent's UCP
    profile. It is an agent-identity requirement rather than an authorization credential; omitting it
    returns JSON-RPC -32001 "UCP discovery failed" / invalid_profile_url with HTTP 422.
  sources: [mcp/abcoffee-mcp-tools.json]
anonymous_access:
  description: >-
    MCP initialize and tools/list are callable with no credential at all (HTTP 200). The read-only
    storefront surface documented in llms.txt (/products/{handle}.json,
    /collections/{handle}/products.json, /search) is also unauthenticated.
  evidence:
  - {url: 'https://abcoffee.in/api/ucp/mcp', method: 'tools/list', status: 200}
  - {url: 'https://abcoffee.in/api/ucp/mcp', method: 'initialize', status: 200}
  - {url: 'https://abcoffee.in/products.json', status: 200}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/abcoffee-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.