generated: '2026-08-05' method: probed source: https://100thieves.com/.well-known/openid-configuration note: >- No OpenAPI exists, so derive-oauth-scopes.py found nothing. These scopes are read verbatim from the scopes_supported array of the live OIDC/OAuth discovery documents served on the 100 Thieves host by Shopify Customer Accounts. Descriptions are ours; the scope strings are the provider's. schemes: - name: shopify-customer-accounts source: https://100thieves.com/.well-known/openid-configuration issuer: https://shopify.com/authentication/31052262 flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/31052262/oauth/authorize tokenUrl: https://shopify.com/authentication/31052262/oauth/token pkce: S256 scopes: - scope: openid description: Standard OpenID Connect scope — requests an ID token for the signed-in customer. flows: [authorizationCode] sources: [well-known/100-thieves-openid-configuration.json] - scope: email description: Releases the customer's email and email_verified claims. flows: [authorizationCode] sources: [well-known/100-thieves-openid-configuration.json] - scope: customer-account-api:full description: Full access to the Shopify Customer Account API on behalf of the signed-in customer — orders, addresses, profile. flows: [authorizationCode] sources: [well-known/100-thieves-openid-configuration.json] - scope: customer-account-mcp-api:full description: Full access to the customer-scoped MCP API on behalf of the signed-in customer. Distinct from the anonymous UCP shopping MCP endpoint at /api/ucp/mcp, which needs no token. flows: [authorizationCode] sources: [well-known/100-thieves-openid-configuration.json] coverage: scopes_total: 4 documented_by_provider: false note: 100 Thieves publishes no scopes reference page of its own; the scope list is machine-readable only, via the discovery document. x-evidence: - url: https://100thieves.com/.well-known/openid-configuration http_status: 200 content_type: application/json