Ubras Authentication
Authentication profile of Ubras's machine-facing surface, captured from the live discovery documents on ubras.com (the international Shopify storefront). Customer identity uses Shopify customer accounts OIDC (issuer https://shopify.com/authentication/52594442401), published at both /.well-known/openid-configuration and /.well-known/oauth-authorization-server (identical documents, saved in well-known/). The storefront MCP endpoint (/api/mcp) and the read-only product JSON endpoints are anonymous; the UCP shopping MCP (/api/ucp/mcp) requires a UCP agent profile rather than an API key. Ubras publishes no separate first-party developer API keys or OAuth program of its own.
Ubras secures its APIs with openIdConnect across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.