generated: '2026-08-04' method: probed source: https://partyshop.paperlesspost.com/.well-known/openid-configuration note: >- Scopes are the `scopes_supported` array advertised by the authorization server that protects the Paperless Post Party Shop storefront. Paperless Post publishes no scope reference of its own; descriptions below state only what each scope literally names. The core www.paperlesspost.com product has no OAuth surface at all. schemes: - name: shopify-customer-account-oidc source: well-known/paperless-post-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://shopify.com/authentication/53345157285/oauth/authorize tokenUrl: https://shopify.com/authentication/53345157285/oauth/token scopes: - scope: openid description: OpenID Connect authentication; returns an ID token for the customer. flows: [authorizationCode] sources: [well-known/paperless-post-openid-configuration.json] - scope: email description: Access to the customer's email address and email_verified claim. flows: [authorizationCode] sources: [well-known/paperless-post-openid-configuration.json] - scope: customer-account-api:full description: Full access to the authenticated customer's account API surface. flows: [authorizationCode] sources: [well-known/paperless-post-openid-configuration.json] - scope: customer-account-mcp-api:full description: Full access to the authenticated customer's account MCP API surface. flows: [authorizationCode] sources: [well-known/paperless-post-openid-configuration.json] x-evidence: fetched: '2026-08-04' url: https://partyshop.paperlesspost.com/.well-known/openid-configuration http_status: 200