Debut · Authentication Profile

Debut Authentication

Authentication

Debut declares 4 security scheme(s) across its OpenAPI definitions.

CompanyBiotechnologyBeautyCosmeticsSkincareIngredientsSynthetic BiologyArtificial IntelligenceManufacturingEcommerceAgentic Commerce
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

none
agentIdentity
openIdConnect
humanApproval

Source

Authentication Profile

debut-authentication.yml Raw ↑
generated: '2026-08-12'
method: probed
source: https://www.deinde.com/.well-known/oauth-authorization-server + live MCP tools/list
  probe of https://www.deinde.com/api/ucp/mcp

api: DEINDE Commerce (UCP MCP)
docs: https://www.deinde.com/llms.txt

summary: >-
  The DEINDE UCP MCP endpoint is anonymously reachable for discovery, catalog, cart and
  checkout construction — an unauthenticated tools/list returned all 13 tools with full
  schemas. There is no API key, and no developer registration. What is gated is money and
  customer data: completing a checkout requires a buyer-approved payment instrument
  supplied through a UCP payment handler, and customer-account operations run through the
  Shopify-operated OAuth 2.0 / OpenID Connect authorization server the store advertises
  from its own host.

schemes:

- id: anonymous
  type: none
  applies_to:
  - tools/list
  - search_catalog
  - lookup_catalog
  - get_product
  - create_cart
  - get_cart
  - update_cart
  - cancel_cart
  - create_checkout
  - get_checkout
  - update_checkout
  - cancel_checkout
  note: >-
    No credential was presented on the probe. The only required request metadata is
    meta["ucp-agent"].profile — a URI naming the calling agent's UCP profile, which the
    server fetches and validates. It is agent identification, not authentication; a
    malformed or unfetchable profile returns JSON-RPC error -32001 profile_malformed.

- id: ucp-agent-profile
  type: agentIdentity
  location: request body
  parameter: meta.ucp-agent.profile
  required: true
  format: uri
  note: >-
    Required on every tool call. Server-side fetched and content-type checked; this is
    the mechanism by which the merchant identifies which agent is transacting.

- id: shopify-customer-oidc
  type: openIdConnect
  openIdConnectUrl: https://www.deinde.com/.well-known/openid-configuration
  issuer: https://shopify.com/authentication/75476861220
  authorization_endpoint: https://account.deinde.com/authentication/oauth/authorize
  token_endpoint: https://account.deinde.com/authentication/oauth/token
  end_session_endpoint: https://account.deinde.com/authentication/logout
  jwks_uri: https://account.deinde.com/authentication/.well-known/jwks.json
  grant_types:
  - authorization_code
  - refresh_token
  - urn:ietf:params:oauth:grant-type:jwt-bearer
  response_types:
  - code
  pkce:
    supported: true
    code_challenge_methods:
    - S256
  token_endpoint_auth_methods:
  - client_secret_basic
  id_token_signing_alg:
  - RS256
  claims:
  - iss
  - sub
  - aud
  - exp
  - iat
  - nonce
  - sid
  - email
  - email_verified
  scopes: scopes/debut-scopes.yml
  applies_to:
  - customer account operations
  - get_order (buyer-scoped order retrieval)
  note: >-
    Operated by Shopify on Debut's behalf. Subject types are public; the resource server
    metadata at /.well-known/oauth-protected-resource names
    https://www.deinde.com as the resource and both https://account.deinde.com and the
    Shopify issuer as authorization servers, with bearer tokens in the Authorization
    header.

- id: buyer-payment-approval
  type: humanApproval
  applies_to:
  - complete_checkout
  note: >-
    The store's published agent instructions state that agents must not complete payment
    without contemporaneous buyer consent, and recommend routing payment through Shop Pay
    via the cross-store Shop skill when consent cannot be obtained in the moment. This is
    a policy control on top of the payment handlers declared in /.well-known/ucp
    (Google Pay among them), not a transport credential.

corporate_site:
  host: www.debutbiotech.com
  authentication: none
  note: >-
    debutbiotech.com is a Webflow marketing site with no login, no account system and no
    API. Nothing to authenticate against.