Cerebelly · Authentication Profile
Cerebelly Authentication
Authentication
Cerebelly publishes no OpenAPI, so this profile is built from the OpenID Connect and OAuth metadata documents its own host serves, plus the observed behaviour of each live endpoint. Three distinct authentication postures coexist on the domain: the commerce agent surfaces are anonymous, the customer-account surface is a full OIDC authorization-code flow with PKCE, and payment authorization is delegated entirely to buyer-approved payment handlers.
Cerebelly declares 4 security scheme(s) across its OpenAPI definitions.
CompanyBaby FoodConsumer Packaged GoodsFood and BeverageE-CommerceRetailDirect to ConsumerShopifyAgentic CommerceUniversal Commerce ProtocolNutrition
Methods:
Schemes: 4
OAuth flows:
API key in:
Security Schemes
none
openIdConnect
http
delegated
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.