bluebarry.
ReviewsPricingResources
Sign inBook demoBook a 15 min demo
Help Center/Developer platform/Use OAuth with bluebarry

Use OAuth with bluebarry

Martijn Douma
Martijn Douma · Co-founder bluebarry
Updated September 25, 2026

OAuth lets an app act on behalf of a bluebarry user, who signs in and approves the connection. No API key changes hands. bluebarry uses it for AI clients that connect to the bluebarry MCP server, and for partner apps that integrate with many bluebarry accounts.

Endpoints

OAuth endpoints
Metadata        https://data.bluebarry.ai/.well-known/oauth-authorization-server
Authorize       https://data.bluebarry.ai/oauth/authorize
Token           https://data.bluebarry.ai/oauth/token
Registration    https://data.bluebarry.ai/register

bluebarry supports the authorization code flow with PKCE (S256) and refresh tokens.

AI clients and the MCP server

MCP clients such as Claude and ChatGPT register themselves through the registration endpoint and ask for the mcp.analytics.read scope. The user signs in to bluebarry and approves access. You do not need to create anything in Studio. See connect bluebarry to Claude and the MCP tool reference.

Partner apps

Self-registered clients can only use the MCP scope. If you are building an app that needs the Data API for other bluebarry merchants, contact us and we register a client for you. Partner clients can get these scopes:

  • api: full Data API access for the signed-in user's account.
  • api.read: read-only access to analytics exports.
  • offline_access: a refresh token, so your app keeps working without the user signing in again.
  • openid, profile, email: who the user is.

The flow

  1. Send the user to the authorize endpoint with your client ID, redirect URI, scopes and a PKCE code challenge.
  2. The user signs in to bluebarry and approves. bluebarry redirects back with a code.
  3. Exchange the code at the token endpoint, with your client secret if your client has one, for an access token and, with offline_access, a refresh token.
  4. Call the Data API with Authorization: Bearer <access token>. Use the refresh token to get a new access token when it expires.

Good to know

  • There is no revoke endpoint. To end a connection, delete the tokens on your side. Contact us if a partner client must be switched off.
  • For your own server-to-server work, an API key is simpler. See manage API keys.

Related articles

API authentication overview

Choose between an API key, an OAuth token and your Tenant ID for the bluebarry Data API, see how to send each, and keep your credentials safe.

Read article →

MCP tool reference

Connect an AI assistant to the read-only bluebarry MCP server and see every tool it offers for quizzes, search, landing pages and profiles.

Read article →

Connect bluebarry to Claude

Add bluebarry as a custom connector in Claude and ask plain-language questions about your quizzes, search and shoppers with read-only access.

Read article →

Can’t figure it out? We probably can.

Every article here was written by the people who built the product. If one of them still leaves you stuck, tell us and we’ll fix it.

Contact usJoin Discord, free forever
bluebarry.

Helping beauty, health and outdoor brands reach their dream AOV

[email protected]+31 6 57 16 10 87De Ried 10, 9285KK Buitenpost (The Netherlands)
Martijn DoumaStan van RooyAnco PostmaJelmer Reitsma

The guys that are increasing your AOV.

Platform
Quiz funnelsLanding pagesProduct QuizRecommendationsSearchIntegrationsPricing
Resources
CasesHelp centerFAQCompare
Company
Contact usPartners & affiliateReviewsRequest demo
Book a 15 min demo
© 2026 bluebarry. All rights reserved.
Privacy PolicyCookie PolicyTerms & Conditions
English/Nederlands/Deutsch
bluebarry