Bobbie · Authentication Profile
Bobbie Authentication
Authentication
Bobbie publishes no OpenAPI, so this profile is built from live discovery documents and observed responses rather than derived securitySchemes. Three distinct auth postures were observed on 2026-08-02.
Bobbie secures its APIs with none, openIdConnect, and oauth2 across 5 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, refreshToken, and jwt-bearer flow(s).
CompanyConsumer Packaged GoodsInfant FormulaEcommerceDirect to ConsumerRetailHealthNutritionAgentic CommerceShopifyGraphQLModel Context Protocol
Methods: none, openIdConnect, oauth2
Schemes: 5
OAuth flows: authorizationCode, refreshToken, jwt-bearer
API key in:
Security Schemes
anonymous-storefront-mcp none
anonymous-storefront-graphql none
shopify-customer-accounts openIdConnect
shopify-customer-accounts-oauth2 oauth2
ucp-agent-profile other