generated: '2026-09-05' method: probed source: https://fourthandheart.com/.well-known/openid-configuration docs: https://fourthandheart.com/agents.md note: >- Derived from probed discovery documents rather than an OpenAPI, because 4th & Heart publishes no OpenAPI. Two distinct auth surfaces exist and they are not the same thing: the agent-commerce MCP server is anonymous, while the customer account surface is OAuth 2.0 / OpenID Connect operated by Shopify on the merchant's behalf. summary: types: [none, oauth2, openIdConnect] api_key_in: [] oauth2_flows: [authorizationCode, refreshToken, jwtBearer] schemes: - name: mcp-anonymous type: none applies_to: https://fourthandheart.com/api/ucp/mcp description: >- The UCP MCP endpoint accepts JSON-RPC tools/list and initialize with no credential of any kind. Verified anonymously, HTTP 200. sources: [https://fourthandheart.com/api/ucp/mcp] - name: ucp-agent-profile type: agent-identity in: body parameter_name: meta.ucp-agent.profile required: true applies_to: tools/call description: >- Every tools/call carries a meta object with a ucp-agent.profile URI identifying the calling agent. It is an identity assertion the server dereferences, not a secret. Omitting it returns JSON-RPC error -32001 with data.code invalid_profile_url. sources: [mcp/4th-heart-mcp-tools.json] - name: shopify-customer-account-oidc type: openIdConnect openIdConnectUrl: https://fourthandheart.com/.well-known/openid-configuration issuer: https://shopify.com/authentication/6414473 applies_to: customer accounts and the customer-account MCP API description: >- Shopify Customer Accounts, published on the merchant's own domain and scoped to shop id 6414473. sources: [well-known/4th-heart-openid-configuration.json] - name: shopify-customer-account-oauth2 type: oauth2 authorizationUrl: https://shopify.com/authentication/6414473/oauth/authorize tokenUrl: https://shopify.com/authentication/6414473/oauth/token end_session_endpoint: https://shopify.com/authentication/6414473/logout jwks_uri: https://shopify.com/authentication/6414473/.well-known/jwks.json flows: [authorization_code, refresh_token, 'urn:ietf:params:oauth:grant-type:jwt-bearer'] pkce: [S256] token_endpoint_auth_methods: [client_secret_basic, client_secret_post] id_token_signing_alg: [RS256] bearer_methods_supported: [header] sources: - well-known/4th-heart-oauth-authorization-server.json - well-known/4th-heart-oauth-protected-resource.json