Brooklinen · Authentication Profile

Brooklinen Authentication

Authentication

Brooklinen secures its APIs with oauth2, openIdConnect, and none across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

E-CommerceRetailDirect to ConsumerHome GoodsBeddingShopifyAgentic CommerceUniversal Commerce ProtocolMCPagent-nativeCatalogCheckout
Methods: oauth2, openIdConnect, none Schemes: 4 OAuth flows: authorizationCode API key in:

Security Schemes

none none
ucp-agent-profile agentIdentity
· in: header ()
shopify-customer-account-oauth2 oauth2
· flows: authorizationCode
shopify-customer-account-oidc openIdConnect

Source

Authentication Profile

Raw ↑
generated: '2026-08-02'
method: probed
source:
- https://www.brooklinen.com/.well-known/oauth-authorization-server
- https://www.brooklinen.com/.well-known/oauth-protected-resource
- https://ucp.dev/2026-04-08/services/shopping/mcp.openrpc.json
summary:
  types: [oauth2, openIdConnect, none]
  api_key_in: []
  oauth2_flows: [authorizationCode]
  pkce: [S256]
  bearer: header
  note: >-
    Brooklinen runs no developer API key program. Two distinct authentication postures exist: the read-only
    storefront JSON surface is fully anonymous, and the transactional UCP/MCP surface is gated by agent
    identity (a resolvable UCP agent profile) with customer authorization handled by Shopify's OAuth 2.0 /
    OIDC customer account issuer.
schemes:
- name: none
  type: none
  applies_to: openapi/brooklinen-storefront-openapi.yml
  description: >-
    The documented read-only storefront JSON endpoints (/products.json, /products/{handle}.json,
    /collections/{handle}/products.json, /search/suggest.json, /cart.js) require no credential. Confirmed by
    anonymous HTTP 200 on each, 2026-08-02.
- name: ucp-agent-profile
  type: agentIdentity
  in: header
  parameter_name: UCP-Agent
  request_property: meta.ucp-agent.profile
  required: true
  applies_to: https://www.brooklinen.com/api/ucp/mcp
  description: >-
    The MCP endpoint requires the calling agent to identify itself with a URI pointing at its own UCP profile
    document, which the merchant fetches. This is agent identity, not user authorization — it gates
    tools/list as well as tool invocation. An anonymous or unresolvable profile returns HTTP 422 with
    JSON-RPC error -32001 (`invalid_profile_url`).
  sources: [https://ucp.dev/2026-04-08/services/shopping/mcp.openrpc.json]
- name: shopify-customer-account-oauth2
  type: oauth2
  applies_to: https://www.brooklinen.com
  description: >-
    OAuth 2.0 authorization code flow with PKCE against Shopify's customer account issuer for this shop,
    fronted on Brooklinen's own account subdomain. Covers customer account data and the customer account MCP
    API.
  issuer: https://shopify.com/authentication/9517126
  flows:
  - flow: authorizationCode
    authorizationUrl: https://account.brooklinen.com/authentication/oauth/authorize
    tokenUrl: https://account.brooklinen.com/authentication/oauth/token
    scopes:
      openid: OpenID Connect authentication.
      email: Access to the customer's email address.
      customer-account-api:full: Full access to the Shopify Customer Account API for this shop.
      customer-account-mcp-api:full: Full access to the Customer Account MCP API for this shop.
  grant_types_supported: [authorization_code, refresh_token, 'urn:ietf:params:oauth:grant-type:jwt-bearer']
  code_challenge_methods_supported: [S256]
  token_endpoint_auth_methods_supported: [client_secret_basic]
  end_session_endpoint: https://account.brooklinen.com/authentication/logout
  sources: [https://www.brooklinen.com/.well-known/oauth-authorization-server]
- name: shopify-customer-account-oidc
  type: openIdConnect
  applies_to: https://www.brooklinen.com
  description: >-
    The same issuer advertises OpenID Connect metadata — JWKS, RS256 id_token signing, and standard claims —
    though no /.well-known/openid-configuration is served at the store origin.
  jwks_uri: https://account.brooklinen.com/authentication/.well-known/jwks.json
  id_token_signing_alg_values_supported: [RS256]
  subject_types_supported: [public]
  response_types_supported: [code]
  claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified]
  sources: [https://www.brooklinen.com/.well-known/oauth-authorization-server]
protected_resource:
  resource: https://www.brooklinen.com
  authorization_servers:
  - https://account.brooklinen.com
  - https://shopify.com/authentication/9517126
  bearer_methods_supported: [header]
  spec: RFC 9728
  sources: [https://www.brooklinen.com/.well-known/oauth-protected-resource]
human_in_the_loop:
  required_for: [complete_checkout]
  policy: >-
    Brooklinen's /agents.md and /robots.txt both state that checkout, payment and order placement must not be
    completed automatically. Agents must obtain explicit, contemporaneous human approval at the moment of
    payment, or route the purchase through Shop Pay via https://shop.app/SKILL.md.
x-evidence:
  fetched: '2026-08-02'
  probes:
  - {url: 'https://www.brooklinen.com/.well-known/oauth-authorization-server', http_status: 200}
  - {url: 'https://www.brooklinen.com/.well-known/oauth-protected-resource', http_status: 200}
  - {url: 'https://www.brooklinen.com/.well-known/openid-configuration', http_status: 404}
  - {url: 'https://www.brooklinen.com/products.json?limit=1', http_status: 200, auth: none}
  - {url: 'https://www.brooklinen.com/api/ucp/mcp', http_status: 422, auth: none}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/brooklinen-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.