generated: '2026-07-31' method: searched source: https://drinkolipop.com/.well-known/openid-configuration notes: >- The only OAuth scope surface on the OLIPOP domain is the Shopify customer-accounts authorization server advertised at /.well-known/openid-configuration (and identically at /.well-known/oauth-authorization-server) for shop id 3466100806. There is no developer-facing OAuth app program and no per-resource scope taxonomy; scopes_supported below is the verbatim published list. The UCP/MCP commerce endpoint does not use OAuth scopes at all - it gates on a UCP platform agent profile plus human buyer approval. schemes: - name: shopifyCustomerAccounts type: openIdConnect source: well-known/olipop-openid-configuration.json issuer: https://shopify.com/authentication/3466100806 flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/3466100806/oauth/authorize tokenUrl: https://shopify.com/authentication/3466100806/oauth/token pkce: S256 scopes: - scope: openid description: Standard OpenID Connect scope requesting an ID token for the authenticated customer. flows: [authorizationCode] sources: [well-known/olipop-openid-configuration.json] - scope: email description: Releases the customer's email address and email_verified claim. flows: [authorizationCode] sources: [well-known/olipop-openid-configuration.json] - scope: customer-account-api:full description: Full access to the Shopify Customer Account API on behalf of the authenticated customer - orders, addresses, subscriptions and profile. flows: [authorizationCode] sources: [well-known/olipop-openid-configuration.json] - scope: customer-account-mcp-api:full description: Full access to the Shopify Customer Account MCP API, the agent-facing projection of the customer account surface. flows: [authorizationCode] sources: [well-known/olipop-openid-configuration.json] x-evidence: fetched: '2026-07-31' url: https://drinkolipop.com/.well-known/openid-configuration http_status: 200