Black Buffalo · Authentication Profile
Black Buffalo Authentication
Authentication
Black Buffalo publishes no OpenAPI, so this profile is built from live discovery documents and observed responses rather than derived securitySchemes. Four distinct auth postures were observed on 2026-08-07 — and notably, THREE of the four machine surfaces answered with no credential at all.
Black Buffalo secures its APIs with none, openIdConnect, oauth2, and agentProfile across 7 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, refreshToken, and jwt-bearer flow(s).
CompanyConsumer Packaged GoodsNicotine PouchesSmokeless Tobacco AlternativeEcommerceDirect to ConsumerRetailAgentic CommerceShopifyGraphQLModel Context ProtocolUniversal Commerce Protocol
Methods: none, openIdConnect, oauth2, agentProfile
Schemes: 7
OAuth flows: authorizationCode, refreshToken, jwt-bearer
API key in:
Security Schemes
anonymous-storefront-graphql none
anonymous-storefront-mcp none
anonymous-ucp-mcp-discovery none
ucp-agent-profile agentProfile
shopify-customer-accounts openIdConnect
shopify-customer-accounts-oauth2 oauth2
storefront-customer-access-token http