generated: '2026-07-31' method: probed source: https://harrys.com/.well-known/openid-configuration note: >- Scopes come from the scopes_supported array of the live OIDC / RFC 8414 discovery documents the two Shopify-hosted brands serve from their own domains. There is no OpenAPI to derive from and Mammoth Brands publishes no scope reference page, so descriptions below are the standard OIDC meanings plus the Shopify Customer Account API scope names verbatim — nothing was invented and no scope was added that the discovery document does not list. schemes: - name: shopify-customer-account-oidc-harrys source: well-known/harry-s-harrys-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/88395284786/oauth/authorize tokenUrl: https://shopify.com/authentication/88395284786/oauth/token pkce: S256 - name: shopify-customer-account-oidc-flamingo source: well-known/harry-s-flamingo-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/55874814054/oauth/authorize tokenUrl: https://shopify.com/authentication/55874814054/oauth/token pkce: S256 scopes: - scope: openid description: Standard OpenID Connect scope; requests an ID token for the authenticated customer. flows: [authorizationCode] sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json] - scope: email description: Releases the customer's email address and email_verified claim. flows: [authorizationCode] sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json] - scope: customer-account-api:full description: Full access to the Shopify Customer Account API on behalf of the signed-in customer (orders, addresses, profile, subscriptions). flows: [authorizationCode] sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json] - scope: customer-account-mcp-api:full description: >- Full access to the customer-account MCP surface on behalf of the signed-in customer — the authenticated counterpart to the anonymous storefront MCP server at /api/mcp. flows: [authorizationCode] sources: [well-known/harry-s-harrys-openid-configuration.json, well-known/harry-s-flamingo-openid-configuration.json] claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified] docs: null docs_note: Mammoth Brands publishes no developer documentation for these scopes; the discovery document is the only source.