Skip to Content
๐Ÿ”‘ Developer PlatformScopes and Merchant Binding

Scopes and Merchant Binding

Scopes define the maximum capabilities an application can request. User consent cannot grant scopes beyond the clientโ€™s approved set.

User identity scopes

ScopeCapabilityMerchant required?
openidPairwise subject and ID TokenNo
profileUsername and nickname, excluding emailNo
emailEmail address and verification statusNo

Email access requires approved email capability and user consent: request openid email or openid profile email. Existing clients are not automatically expanded. Administrators can review scope changes in the OAuth client review screen; changes revoke existing user grants and tokens and require new user consent.

openid requires a nonce. A โ€œSign in with TD Cloudโ€ integration normally requests only openid profile.

Merchant and transaction scopes

ScopeCapabilityActor
merchant.profile.readRead bound merchant public profileUser or Client Credentials
products.writeCreate/update bound-merchant external API productsClient Credentials only
inventory.writeUpdate bound-merchant virtual inventoryClient Credentials only
merchant_payments.createCreate an amount-based collection and replay failed notificationsClient Credentials only
merchant_payments.readRead this merchantโ€™s collections, channels and notification deliveriesClient Credentials only
products.readRead enabled products for the bound merchantUser or Client Credentials
orders.createCreate an order for the authorized userUser only
orders.readRead orders belonging to the authorized user and bound merchantUser only
payments.createStart payment for an accessible orderUser only
payments.readRead payment status for an accessible orderUser only

Enforced merchant binding

If any merchant or transaction scope is requested, the server ignores a client-supplied merchant number and binds the applicantโ€™s own approved, active merchant.

This means:

  • a sign-in client does not require a merchant;
  • merchant scopes cannot be requested without an active merchant;
  • a client cannot name another accountโ€™s merchant;
  • related OpenAPI calls fail after the bound merchant is disabled;
  • switching back to identity-only scopes removes the merchant association.

Client Credentials restriction

Only a confidential, merchant-bound client can use client_credentials. The current flow allows only:

Allowed scopes
merchant.profile.read products.read products.write inventory.write merchant_payments.create merchant_payments.read

Catalog-order orders.* and payments.* still require user authorization. merchant_payments.* is for server-side collection independent of buyer accounts; checkout sign-in depends on merchant policy and channel. See General merchant collection. Request only needed, approved scopes from the supported set above.

Client Credentials
curl -X POST "{TOKEN_ENDPOINT}" \ -H "Content-Type: application/x-www-form-urlencoded" \ --data-urlencode "grant_type=client_credentials" \ --data-urlencode "client_id={CLIENT_ID}" \ --data-urlencode "client_secret={CLIENT_SECRET}" \ --data-urlencode "scope=merchant.profile.read products.read"
Last updated on