generated: '2026-08-04' method: probed source: https://shop.katefarms.com/.well-known/openid-configuration docs: https://shopify.dev/docs/api/customer schemes: - name: CustomerAccountsOIDC source: well-known/kate-farms-openid-configuration.json issuer: https://shopify.com/authentication/2056802 flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/2056802/oauth/authorize tokenUrl: https://shopify.com/authentication/2056802/oauth/token pkce: S256 scopes: - scope: openid description: Standard OIDC scope; requests an ID token identifying the signed-in Kate Farms shopper. flows: - authorizationCode sources: - well-known/kate-farms-openid-configuration.json - scope: email description: Releases the shopper's email and email_verified claims. flows: - authorizationCode sources: - well-known/kate-farms-openid-configuration.json - scope: 'customer-account-api:full' description: Full access to the Customer Account API on behalf of the signed-in shopper — orders, subscriptions, addresses and profile for this store. flows: - authorizationCode sources: - well-known/kate-farms-openid-configuration.json - scope: 'customer-account-mcp-api:full' description: Full access to the Customer Account MCP API — the agent-facing projection of the shopper's account, which is what lets an enrolled agent act on a Kate Farms customer's behalf. flows: - authorizationCode sources: - well-known/kate-farms-openid-configuration.json notes: - Only four scopes are advertised, and two of them are coarse ":full" grants. There is no read-only variant of either the Customer Account API or the Customer Account MCP API on this discovery document, so an agent acting for a shopper is granted the whole account surface or nothing. - These are the shopper-identity scopes. Anonymous storefront reads (catalog, collections, search, blog, pages) need no scope at all. x-evidence: fetched: '2026-08-04' url: https://shop.katefarms.com/.well-known/openid-configuration http_status: 200 content_type: application/json