generated: '2026-08-05' method: searched source: https://www.therabody.com/.well-known/openid-configuration docs: https://account.therabody.com/.well-known/oauth-authorization-server schemes: - name: ShopifyCustomerAccountOIDC issuer: https://shopify.com/authentication/67140976867 source: well-known/therabody-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://account.therabody.com/authentication/oauth/authorize tokenUrl: https://account.therabody.com/authentication/oauth/token pkce: S256 scopes: - scope: openid description: OpenID Connect authentication; issues an ID token identifying the customer. flows: - authorizationCode sources: - well-known/therabody-openid-configuration.json - scope: email description: Access to the customer email address and email_verified claim. flows: - authorizationCode sources: - well-known/therabody-openid-configuration.json - scope: customer-account-api:full description: Full access to the Shopify Customer Account API for the authenticated customer (orders, addresses, payment methods, profile). flows: - authorizationCode sources: - well-known/therabody-openid-configuration.json - scope: customer-account-mcp-api:full description: Full access to the Customer Account MCP tool surface for the authenticated customer (order status, store credit balances, return requests). flows: - authorizationCode sources: - well-known/therabody-openid-configuration.json note: Scopes are published by the customer-account authorization server discovery document, not by an OpenAPI securityScheme — Therabody publishes no OpenAPI. The UCP commerce MCP server is not scope-gated; it gates checkout completion on explicit buyer approval instead.