Cerebelly · Authentication Profile
Cerebelly Authentication
Authentication
Cerebelly publishes no OpenAPI, so this profile is built from the OpenID Connect and OAuth metadata documents its own host serves, plus the observed behaviour of each live endpoint. Three distinct authentication postures coexist on the domain: the commerce agent surfaces are anonymous, the customer-account surface is a full OIDC authorization-code flow with PKCE, and payment authorization is delegated entirely to buyer-approved payment handlers.
Cerebelly declares 4 security scheme(s) across its OpenAPI definitions.
CompanyBaby FoodConsumer Packaged GoodsFood and BeverageeCommerceRetailDirect to ConsumerShopifyAgentic CommerceUniversal Commerce ProtocolNutrition
Methods:
Schemes: 4
OAuth flows:
API key in:
Security Schemes
none
openIdConnect
http
delegated