Supergoop! · Authentication Profile

Supergoop Authentication

Authentication

Supergoop! has no developer program and issues no API keys. Its machine surfaces authenticate in three distinct ways, all observed live on 2026-08-29.

Supergoop! declares 5 security scheme(s) across its OpenAPI definitions.

CompanySunscreenSkincareBeautyCosmeticsConsumer GoodsRetailE-CommerceDirect to ConsumerShopifyAgentic CommerceUniversal Commerce ProtocolMCPGraphQL
Methods: Schemes: 5 OAuth flows: API key in:

Security Schemes

none
agent-profile
http
scheme: bearer
openIdConnect
X-Shopify-Customer-Access-Token apiKey

Source

Authentication Profile

supergoop-authentication.yml Raw ↑
generated: '2026-08-29'
method: probed
source: >-
  https://supergoop.com/.well-known/oauth-authorization-server ;
  https://supergoop.com/.well-known/oauth-protected-resource ;
  https://supergoop.com/api/ucp/mcp ; https://supergoop.com/api/2026-07/graphql.json
description: >-
  Supergoop! has no developer program and issues no API keys. Its machine
  surfaces authenticate in three distinct ways, all observed live on 2026-08-29.
schemes:
  - id: anonymous-public-read
    type: none
    applies_to:
      - https://supergoop.com/api/2026-07/graphql.json (catalog, collections, blog, pages, cart)
      - https://supergoop.com/products.json
      - https://supergoop.com/collections/{handle}/products.json
      - 'POST https://supergoop.com/api/ucp/mcp method=tools/list'
    evidence: >-
      Full GraphQL introspection and a products query both returned HTTP 200 with
      no Authorization header and no X-Shopify-Storefront-Access-Token.
  - id: ucp-agent-profile
    type: agent-profile
    applies_to:
      - 'POST https://supergoop.com/api/ucp/mcp tools/call (catalog + cart + checkout tools)'
    parameter: meta['ucp-agent'].profile
    location: request body (JSON-RPC params.arguments.meta)
    required: true
    description: >-
      Every UCP tool call carries a `meta.ucp-agent.profile` URI identifying the
      calling agent. The server FETCHES that URI; an unreachable profile is
      rejected with JSON-RPC error -32001 / profile_unreachable and HTTP 422. This
      is identity-by-published-document rather than a bearer credential.
    evidence: examples/supergoop-ucp-mcp-error-profile-unreachable.json
  - id: ucp-jwt
    type: http
    scheme: bearer
    format: JWT
    applies_to:
      - 'POST https://supergoop.com/api/ucp/mcp tools/call name=get_order'
    required: true
    description: >-
      Order-scoped tools require a JWT. An anonymous call returned HTTP 403 with
      JSON-RPC error -32000 AuthenticationRequired and a pointer to
      https://shopify.dev/docs/agents/get-started/authentication.
    evidence: examples/supergoop-ucp-mcp-error-authentication-required.json
  - id: shopify-customer-accounts-oidc
    type: openIdConnect
    openIdConnectUrl: https://supergoop.com/.well-known/openid-configuration
    applies_to:
      - https://supergoop.com/account (shopper sign-in)
      - Customer Account API / customer-account-mcp-api
    issuer: https://shopify.com/authentication/15035658
    authorization_endpoint: https://shopify.com/authentication/15035658/oauth/authorize
    token_endpoint: https://shopify.com/authentication/15035658/oauth/token
    end_session_endpoint: https://shopify.com/authentication/15035658/logout
    jwks_uri: https://shopify.com/authentication/15035658/.well-known/jwks.json
    grant_types: [authorization_code, refresh_token, 'urn:ietf:params:oauth:grant-type:jwt-bearer']
    response_types: [code]
    pkce: [S256]
    token_endpoint_auth_methods: [client_secret_basic, client_secret_post]
    id_token_signing_alg: [RS256]
    scopes: [openid, email, 'customer-account-api:full', 'customer-account-mcp-api:full']
    description: >-
      Shopper identity for supergoop.com is an OIDC provider hosted by Shopify on
      behalf of this store (shop id 15035658). The discovery documents are served
      from supergoop.com; the issuer and endpoints are on shopify.com.
  - id: storefront-customer-access-token
    type: apiKey
    name: X-Shopify-Customer-Access-Token
    location: header
    applies_to:
      - Storefront GraphQL customer{} field and customer* mutations
    description: >-
      Customer-scoped Storefront GraphQL fields take a customer access token
      minted by Mutation.customerAccessTokenCreate. Present in the live schema;
      not exercised.
notes:
  - No API keys, client credentials, or partner registration are offered by Supergoop! itself.
  - >-
    No developer portal exists. The authentication surface is entirely the
    Shopify commerce platform's, exposed on Supergoop!'s domain.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/supergoop-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.