Kite Hill · Authentication Profile
Kite Hill Authentication
Authentication
Kite Hill publishes no OpenAPI, so this profile is built from live discovery documents and observed responses rather than derived securitySchemes. Five distinct auth postures were observed on 2026-08-23 — and notably, THREE of the machine surfaces answered with no credential at all.
Kite Hill secures its APIs with none, openIdConnect, oauth2, agentProfile, and http across 7 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, refreshToken, and jwt-bearer flow(s).
CompanyConsumer Packaged GoodsPlant Based FoodsDairy AlternativesFood and BeverageE-CommerceDirect to ConsumerRetailAgentic CommerceShopifyGraphQLMCPUniversal Commerce Protocol
Methods: none, openIdConnect, oauth2, agentProfile, http
Schemes: 7
OAuth flows: authorizationCode, refreshToken, jwt-bearer
API key in:
Security Schemes
anonymous-storefront-graphql none
anonymous-storefront-mcp none
anonymous-ucp-mcp-discovery none
ucp-agent-profile agentProfile
shopify-customer-accounts openIdConnect
shopify-customer-accounts-oauth2 oauth2
storefront-customer-access-token http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.