Sambazon · Authentication Profile
Sambazon Authentication
Authentication
SAMBAZON has no developer program and issues no API keys. Authentication on its public surface comes from two places: (1) nothing at all — the read-only Shopify storefront JSON endpoints and the discovery documents are unauthenticated; and (2) the Shopify customer-account OpenID Connect provider, whose metadata this origin publishes and whose authorization server is Shopify's, not SAMBAZON's. The UCP/MCP endpoint is a third case: it is not key- or token-gated but PROFILE-gated — it requires the calling agent to present a resolvable UCP agent profile URI before it will do anything.
Sambazon declares 3 security scheme(s) across its OpenAPI definitions.
CompanyFood and BeverageConsumer Packaged GoodsEcommerceAgentic CommerceUniversal Commerce ProtocolModel Context ProtocolShopifyRetailSustainability
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
none
agent-identity
openIdConnect