# Webloyalty > Webloyalty is a customer-engagement and loyalty-marketing company (a Tenerity / > former Affinion Group brand) whose rewards platform is placed on a retail > partner's ecommerce confirmation page, delivering cashback and shopping savings > to consumers while generating secondary revenue for the partner. It operates > localized programs across the UK, Ireland, France, Spain, the Netherlands, > Switzerland, Turkey, Mexico and the United States. This file was GENERATED by API Evangelist from the catalog profile and the artifacts in this repository. Webloyalty does not publish an llms.txt of its own (https://webloyalty.co.uk/llms.txt and https://webloyalty.com/llms.txt both return HTTP 404), and it publishes no developer portal, API reference or OpenAPI. Everything below was probed or searched on 2026-08-13. ## What is actually callable - [MCP endpoint](https://webloyalty.co.uk/wp-json/mcp/mcp-oauth-server): a live, OAuth-protected Model Context Protocol server hosted inside the UK site's WordPress REST API. `tools/list` returns HTTP 401 `mcp_unauthorized` without a token, so the tool set is not publicly enumerable. - [Second MCP server](https://webloyalty.co.uk/wp-json/mcp/mcp-adapter-default-server): same namespace, guarded by WordPress permissions (HTTP 401 `rest_forbidden`). - [WordPress REST API index](https://webloyalty.co.uk/wp-json/): anonymous route listing only (317 routes, 16 namespaces). Every data route probed returns HTTP 401 — the REST API is locked down. - There is no public REST/GraphQL product API. The company's commercial integration is described only as "bespoke API solutions" on its marketing site and is arranged through sales. ## Authorization - [Authorization server metadata](https://webloyalty.co.uk/.well-known/oauth-authorization-server) (RFC 8414) — issuer `https://webloyalty.co.uk`, authorization code + refresh token, PKCE `S256` required, public clients only (`token_endpoint_auth_methods_supported: ["none"]`), client-ID metadata documents supported. - [Protected resource metadata](https://webloyalty.co.uk/.well-known/oauth-protected-resource) (RFC 9728) — names the MCP resource, bearer token in the header. - Single scope: `mcp`. - Endpoints: authorize `https://webloyalty.co.uk/oauth/authorize`, token `https://webloyalty.co.uk/oauth/token`, revoke `https://webloyalty.co.uk/oauth/revoke`. ## Client libraries - [tenerity-blender-rn-sdk](https://www.npmjs.com/package/tenerity-blender-rn-sdk) — React Native SDK that embeds Webloyalty campaign banners (inline + overlay) in a partner's mobile app. `v3.0.4`, published 2025-10-30. Requires a `campaignId` issued by Webloyalty. The README is the only reference published. ## Company pages - [Webloyalty UK](https://webloyalty.co.uk/) - [Locale index](http://webloyalty.com/world) — links to the .co.uk, .ie, .fr, .es, .ch, .com.tr, .mx sites - [What we offer](https://webloyalty.co.uk/what-we-offer/) — Complete Savings, White Label, bespoke API solutions - [Intelligence Centre](https://webloyalty.co.uk/intelligence-centre/) - [News & Views](https://webloyalty.co.uk/news-views/) — blog, RSS at https://webloyalty.co.uk/feed/ - [Contact](https://webloyalty.co.uk/contact-us/) - [Regulatory](https://webloyalty.co.uk/regulatory/) — registered in England No. 05922626, VAT GB 125 4954 08 - [Terms](https://webloyalty.co.uk/terms-conditions/) · [Privacy & cookies](https://webloyalty.co.uk/privacy-cookies-policy/) ## Not published No OpenAPI, AsyncAPI or GraphQL schema. No agent card (`/.well-known/agent-card.json` and `/.well-known/agent.json` both 404 on every host). No security.txt, no api-catalog, no ai-plugin.json, no OpenID Connect discovery. No status page, no changelog for any API, no documented rate limits, no published pricing, no vulnerability-disclosure program and no trust center.