OAuth lets an app act on behalf of a bluebarry user, who signs in and approves the connection. No API key changes hands. bluebarry uses it for AI clients that connect to the bluebarry MCP server, and for partner apps that integrate with many bluebarry accounts.
Endpoints
Metadata https://data.bluebarry.ai/.well-known/oauth-authorization-server
Authorize https://data.bluebarry.ai/oauth/authorize
Token https://data.bluebarry.ai/oauth/token
Registration https://data.bluebarry.ai/registerbluebarry supports the authorization code flow with PKCE (S256) and refresh tokens.
AI clients and the MCP server
MCP clients such as Claude and ChatGPT register themselves through the registration endpoint and ask for the mcp.analytics.read scope. The user signs in to bluebarry and approves access. You do not need to create anything in Studio. See connect bluebarry to Claude and the MCP tool reference.
Partner apps
Self-registered clients can only use the MCP scope. If you are building an app that needs the Data API for other bluebarry merchants, contact us and we register a client for you. Partner clients can get these scopes:
api: full Data API access for the signed-in user's account.api.read: read-only access to analytics exports.offline_access: a refresh token, so your app keeps working without the user signing in again.openid,profile,email: who the user is.
The flow
- Send the user to the authorize endpoint with your client ID, redirect URI, scopes and a PKCE code challenge.
- The user signs in to bluebarry and approves. bluebarry redirects back with a code.
- Exchange the code at the token endpoint, with your client secret if your client has one, for an access token and, with
offline_access, a refresh token. - Call the Data API with
Authorization: Bearer <access token>. Use the refresh token to get a new access token when it expires.
Good to know
- There is no revoke endpoint. To end a connection, delete the tokens on your side. Contact us if a partner client must be switched off.
- For your own server-to-server work, an API key is simpler. See manage API keys.