generated: '2026-09-05' method: probed source: https://www.3neyecare.com/.well-known/openid-configuration docs: null note: >- Read from scopes_supported in the OpenID Connect discovery document the storefront serves. There is no OpenAPI in this repo to derive from, and 3N TECH publishes no scope reference page of its own — these are the Shopify Customer Account scopes advertised under 3N's host. schemes: - name: shopify-customer-account-oidc source: well-known/3ntech-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://account.3neyecare.com/authentication/oauth/authorize tokenUrl: https://account.3neyecare.com/authentication/oauth/token pkce: S256 scopes: - scope: openid description: Standard OpenID Connect scope; requests an ID token for the customer. flows: [authorizationCode] sources: [well-known/3ntech-openid-configuration.json] - scope: email description: Releases the customer's email address and email_verified claim. flows: [authorizationCode] sources: [well-known/3ntech-openid-configuration.json] - scope: customer-account-api:full description: Full access to the authenticated customer's account API surface (orders, addresses, profile). flows: [authorizationCode] sources: [well-known/3ntech-openid-configuration.json] - scope: customer-account-mcp-api:full description: >- Full access to the customer-account MCP surface — an authenticated, per-customer MCP API distinct from the anonymous storefront UCP endpoint. flows: [authorizationCode] sources: [well-known/3ntech-openid-configuration.json]