Hubble Contacts · Authentication Profile
Hubble Contacts Authentication
Authentication
Hubble Contacts secures its APIs with oauth2, openIdConnect, http, and none across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
CompanyE-CommerceRetailHealthVision CareContact LensesSubscriptionAgentic CommerceMCPShopifyGraphQL
Methods: oauth2, openIdConnect, http, none
Schemes: 2
OAuth flows: authorizationCode
API key in:
Security Schemes
shopify-customer-accounts-oidc openIdConnect
shopify-oauth-authorization-server oauth2
· flows: authorizationCode
Source
Authentication Profile
generated: '2026-08-04'
method: searched
source: https://account.hubblecontacts.com/.well-known/openid-configuration
docs: https://account.hubblecontacts.com/agents.md
notes: >-
Hubble Contacts publishes no OpenAPI, so this profile is not derived from
securitySchemes — it is read directly from the OAuth 2.0 / OpenID Connect discovery
documents the storefront host serves, plus the observed auth behaviour of the two
public surfaces. The authorization server is the Shopify customer accounts issuer
bound to Hubble's shop id 15165228; the protected resource is Hubble's own host.
summary:
types: [oauth2, openIdConnect, http, none]
oauth2_flows: [authorizationCode]
pkce: [S256]
bearer_methods: [header]
api_key_in: []
schemes:
- name: shopify-customer-accounts-oidc
type: openIdConnect
openIdConnectUrl: https://account.hubblecontacts.com/.well-known/openid-configuration
issuer: https://shopify.com/authentication/15165228
authorization_endpoint: https://shopify.com/authentication/15165228/oauth/authorize
token_endpoint: https://shopify.com/authentication/15165228/oauth/token
end_session_endpoint: https://shopify.com/authentication/15165228/logout
jwks_uri: https://shopify.com/authentication/15165228/.well-known/jwks.json
response_types_supported: [code]
grant_types_supported:
- authorization_code
- refresh_token
- 'urn:ietf:params:oauth:grant-type:jwt-bearer'
token_endpoint_auth_methods_supported: [client_secret_basic]
code_challenge_methods_supported: [S256]
id_token_signing_alg_values_supported: [RS256]
subject_types_supported: [public]
claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified]
scopes_supported:
- openid
- email
- 'customer-account-api:full'
- 'customer-account-mcp-api:full'
applies_to: Customer account access (order history, subscription management)
source: well-known/hubble-contacts-openid-configuration.json
- name: shopify-oauth-authorization-server
type: oauth2
metadata: https://account.hubblecontacts.com/.well-known/oauth-authorization-server
standard: RFC 8414
issuer: https://shopify.com/authentication/15165228
flows:
- flow: authorizationCode
authorizationUrl: https://shopify.com/authentication/15165228/oauth/authorize
tokenUrl: https://shopify.com/authentication/15165228/oauth/token
pkce: S256
source: well-known/hubble-contacts-oauth-authorization-server.json
protected_resources:
- resource: https://account.hubblecontacts.com
standard: RFC 9728
metadata: https://account.hubblecontacts.com/.well-known/oauth-protected-resource
authorization_servers: ['https://shopify.com/authentication/15165228']
bearer_methods_supported: [header]
source: well-known/hubble-contacts-oauth-protected-resource.json
- name: shopify-storefront-customer-access-token
type: http
scheme: bearer-like custom token
surface: Storefront GraphQL
issued_by: 'mutation customerAccessTokenCreate(input: {email, password})'
renewed_by: customerAccessTokenRenew
revoked_by: customerAccessTokenDelete
passed_as: 'customerAccessToken argument on customer-scoped fields and cart mutations'
applies_to: 'Customer-scoped reads/writes on the Storefront GraphQL surface (customer profile, addresses, orders)'
source: graphql/hubble-contacts-storefront.graphql
note: >-
Found in round 2. Distinct from the OIDC customer-accounts issuer above: this is
the legacy Storefront-API token exchange, which Shopify is steering to the
Customer Account API. Anonymous callers reach everything else on the surface.
surfaces:
- surface: Storefront GraphQL
base: 'https://account.hubblecontacts.com/api/{version}/graphql.json'
auth: none
observed: >-
Round 2. POST with no X-Shopify-Storefront-Access-Token and no bearer token
returned HTTP 200 for a full introspection query (416 types) and for real data
queries (shop { name } returned "Hubble Contacts"). The server labelled the call
graphql;desc="storefront/query/anonymous". Only customer-scoped fields require a
customerAccessToken. This is the most open surface on the property and it is
documented nowhere by Hubble.
- surface: Storefront Product JSON
base: https://account.hubblecontacts.com
auth: none
observed: >-
GET /products.json, /products/{handle}.json, /collections/{handle}/products.json
and /search all return HTTP 200 with no credentials.
- surface: UCP Commerce MCP
base: https://account.hubblecontacts.com/api/ucp/mcp
auth: ucp-agent-profile
observed: >-
Anonymous JSON-RPC returns HTTP 422 / -32001 invalid_profile_url. The gate is a
registered UCP agent profile URI rather than an OAuth bearer challenge; no
WWW-Authenticate header was returned. Buyer-side payment is separately gated on
explicit human approval per Hubble's /agents.md.
- surface: Marketing site
base: https://www.hubblecontacts.com
auth: none
observed: No auth-bearing API surface; no /.well-known/ documents served.
x-evidence:
fetched: '2026-08-04'
probes:
- {url: 'https://account.hubblecontacts.com/.well-known/openid-configuration', http_status: 200}
- {url: 'https://account.hubblecontacts.com/.well-known/oauth-authorization-server', http_status: 200}
- {url: 'https://account.hubblecontacts.com/.well-known/oauth-protected-resource', http_status: 200}
- {url: 'https://account.hubblecontacts.com/api/ucp/mcp', method: POST, http_status: 422}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hubble-contacts-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.