generated: '2026-09-16' method: probed source: >- https://underdog.shop/.well-known/openid-configuration, https://underdog.shop/.well-known/oauth-authorization-server, https://underdog.shop/.well-known/oauth-protected-resource, https://account.underdog.shop/.well-known/oauth-protected-resource, https://underdog.shop/api/ucp/mcp and https://underdog.shop/api/2026-01/graphql.json (anonymous probes) note: >- Underdog runs no developer programme and issues no API keys. Three auth postures exist on its host and should not be conflated. (1) Discovery on the agent/storefront surfaces is anonymous: MCP initialize and tools/list on /api/ucp/mcp and /api/mcp, Storefront GraphQL introspection and product/shop queries, and /products.json all answered HTTP 200 with no credentials on 2026-09-16. (2) UCP tools/call requires the calling agent to identify itself with meta.ucp-agent.profile, a reachable UCP agent profile URI (an unreachable profile returned -32001 "UCP discovery failed"), and get_order returned -32000 AuthenticationRequired "A valid JWT is required", pointing at https://shopify.dev/docs/agents/get-started/authentication. Payment additionally requires contemporaneous human buyer approval (agents.md). (3) Shopper accounts use OAuth 2.0 authorization code + PKCE against Shopify customer accounts, discovered from metadata served on Underdog's own hosts (issuer shopify.com/authentication/69142905142). docs: https://underdog.shop/agents.md summary: types: [none, oauth2, openIdConnect, http] api_key_in: [] oauth2_flows: [authorizationCode] agent_surface_auth: none (discovery); UCP agent profile + JWT for some tool calls human_approval_required_for: [complete_checkout] schemes: - name: anonymous-discovery type: none applies_to: - https://underdog.shop/api/ucp/mcp (initialize, tools/list) - https://underdog.shop/api/mcp - https://underdog.shop/api/2026-01/graphql.json - https://underdog.shop/products.json evidence: probed 2026-09-16, HTTP 200 with no Authorization header - name: ucp-agent-profile type: none location: JSON-RPC params.arguments.meta.ucp-agent.profile description: Agent profile URI the merchant fetches for UCP capability negotiation; required on every UCP tool. evidence: mcp/underdog-ucp-mcp-tools.json (meta.required includes ucp-agent); tools/call with an unreachable profile returned HTTP 422, code -32001 - name: shopify-agent-jwt type: http scheme: bearer bearerFormat: JWT applies_to: [get_order] evidence: tools/call get_order returned HTTP 403, JSON-RPC -32000 AuthenticationRequired, 2026-09-16 docs: https://shopify.dev/docs/agents/get-started/authentication - name: shopify-customer-account-oauth2 type: oauth2 scheme: bearer bearer_methods_supported: [header] flows: - flow: authorizationCode issuer: https://shopify.com/authentication/69142905142 authorizationUrl: https://account.underdog.shop/authentication/oauth/authorize tokenUrl: https://account.underdog.shop/authentication/oauth/token jwksUri: https://account.underdog.shop/authentication/.well-known/jwks.json endSessionEndpoint: https://account.underdog.shop/authentication/logout code_challenge_methods_supported: [S256] token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post] grant_types_supported: [authorization_code, refresh_token, 'urn:ietf:params:oauth:grant-type:jwt-bearer'] scopes: [openid, email, 'customer-account-api:full', 'customer-account-mcp-api:full'] protected_resources: [https://underdog.shop, https://account.underdog.shop] authorization_servers: [https://account.underdog.shop, https://shopify.com/authentication/69142905142] sources: - well-known/underdog-openid-configuration.json - well-known/underdog-oauth-authorization-server.json - well-known/underdog-oauth-protected-resource.json - well-known/underdog-account-oauth-protected-resource.json - name: shopify-customer-account-oidc type: openIdConnect openIdConnectUrl: https://underdog.shop/.well-known/openid-configuration id_token_signing_alg_values_supported: [RS256] subject_types_supported: [public] claims_supported: [iss, sub, aud, exp, iat, nonce, sid, email, email_verified] sources: [well-known/underdog-openid-configuration.json]