generated: '2026-08-08' method: probed source: https://shop.bulletproof.com/.well-known/openid-configuration note: >- Scopes come from the live OAuth 2.0 / OpenID Connect discovery documents served on the Bulletproof hosts (identical payload at shop., account. and the myshopify origin). Bulletproof publishes no scope reference page of its own — these four are the complete scopes_supported list as advertised, nothing has been added. issuer: https://shopify.com/authentication/434700319 schemes: - name: customer-accounts type: openIdConnect source: https://shop.bulletproof.com/.well-known/openid-configuration flows: - flow: authorizationCode authorizationUrl: https://account.bulletproof.com/authentication/oauth/authorize tokenUrl: https://account.bulletproof.com/authentication/oauth/token pkce: S256 scopes: - scope: openid description: Standard OpenID Connect scope; requests an ID token for the signed-in customer. flows: [authorizationCode] sources: ['well-known/bulletproof-openid-configuration.json'] - scope: email description: Releases the customer's email address and email_verified claim. flows: [authorizationCode] sources: ['well-known/bulletproof-openid-configuration.json'] - scope: customer-account-api:full description: >- Full access to the customer account API for the signed-in customer — profile, addresses, orders and subscriptions. flows: [authorizationCode] sources: ['well-known/bulletproof-openid-configuration.json'] - scope: customer-account-mcp-api:full description: >- Full access to the customer account MCP API — the agent-facing projection of the same customer account data. Notable as an explicitly agent-scoped grant. flows: [authorizationCode] sources: ['well-known/bulletproof-openid-configuration.json'] claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified] gaps: - >- The UCP MCP endpoint at /api/ucp/mcp requires a JWT for order and checkout tools but does not advertise which of these scopes mints it; the error body points at shopify.dev rather than a Bulletproof-owned page.