Debut · Authentication Profile

Debut Authentication

Authentication

Debut declares 4 security scheme(s) across its OpenAPI definitions.

CompanyBiotechnologyBeautyCosmeticsSkincareIngredientsSynthetic BiologyArtificial IntelligenceManufacturingE-CommerceAgentic Commerce
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

none
agentIdentity
openIdConnect
humanApproval

Source

Authentication Profile

debut-authentication.yml Raw ↑
generated: '2026-08-12'
method: probed
source: https://www.deinde.com/.well-known/oauth-authorization-server + live MCP tools/list
  probe of https://www.deinde.com/api/ucp/mcp

api: DEINDE Commerce (UCP MCP)
docs: https://www.deinde.com/llms.txt

summary: >-
  The DEINDE UCP MCP endpoint is anonymously reachable for discovery, catalog, cart and
  checkout construction — an unauthenticated tools/list returned all 13 tools with full
  schemas. There is no API key, and no developer registration. What is gated is money and
  customer data: completing a checkout requires a buyer-approved payment instrument
  supplied through a UCP payment handler, and customer-account operations run through the
  Shopify-operated OAuth 2.0 / OpenID Connect authorization server the store advertises
  from its own host.

schemes:

- id: anonymous
  type: none
  applies_to:
  - tools/list
  - search_catalog
  - lookup_catalog
  - get_product
  - create_cart
  - get_cart
  - update_cart
  - cancel_cart
  - create_checkout
  - get_checkout
  - update_checkout
  - cancel_checkout
  note: >-
    No credential was presented on the probe. The only required request metadata is
    meta["ucp-agent"].profile — a URI naming the calling agent's UCP profile, which the
    server fetches and validates. It is agent identification, not authentication; a
    malformed or unfetchable profile returns JSON-RPC error -32001 profile_malformed.

- id: ucp-agent-profile
  type: agentIdentity
  location: request body
  parameter: meta.ucp-agent.profile
  required: true
  format: uri
  note: >-
    Required on every tool call. Server-side fetched and content-type checked; this is
    the mechanism by which the merchant identifies which agent is transacting.

- id: shopify-customer-oidc
  type: openIdConnect
  openIdConnectUrl: https://www.deinde.com/.well-known/openid-configuration
  issuer: https://shopify.com/authentication/75476861220
  authorization_endpoint: https://account.deinde.com/authentication/oauth/authorize
  token_endpoint: https://account.deinde.com/authentication/oauth/token
  end_session_endpoint: https://account.deinde.com/authentication/logout
  jwks_uri: https://account.deinde.com/authentication/.well-known/jwks.json
  grant_types:
  - authorization_code
  - refresh_token
  - urn:ietf:params:oauth:grant-type:jwt-bearer
  response_types:
  - code
  pkce:
    supported: true
    code_challenge_methods:
    - S256
  token_endpoint_auth_methods:
  - client_secret_basic
  id_token_signing_alg:
  - RS256
  claims:
  - iss
  - sub
  - aud
  - exp
  - iat
  - nonce
  - sid
  - email
  - email_verified
  scopes: scopes/debut-scopes.yml
  applies_to:
  - customer account operations
  - get_order (buyer-scoped order retrieval)
  note: >-
    Operated by Shopify on Debut's behalf. Subject types are public; the resource server
    metadata at /.well-known/oauth-protected-resource names
    https://www.deinde.com as the resource and both https://account.deinde.com and the
    Shopify issuer as authorization servers, with bearer tokens in the Authorization
    header.

- id: buyer-payment-approval
  type: humanApproval
  applies_to:
  - complete_checkout
  note: >-
    The store's published agent instructions state that agents must not complete payment
    without contemporaneous buyer consent, and recommend routing payment through Shop Pay
    via the cross-store Shop skill when consent cannot be obtained in the moment. This is
    a policy control on top of the payment handlers declared in /.well-known/ucp
    (Google Pay among them), not a transport credential.

corporate_site:
  host: www.debutbiotech.com
  authentication: none
  note: >-
    debutbiotech.com is a Webflow marketing site with no login, no account system and no
    API. Nothing to authenticate against.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/debut-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.