generated: '2026-09-16' method: probed source: https://underdog.shop/.well-known/openid-configuration note: >- Scopes advertised in scopes_supported by the authorization server Underdog's storefront names for shopper accounts (Shopify customer accounts, issuer https://shopify.com/authentication/69142905142, endpoints on account.underdog.shop). They govern a signed-in shopper's own account, not a developer programme — Underdog publishes none. Only the four strings the document returns are recorded; descriptions state the scope semantics conservatively. schemes: - name: shopify-customer-account-oauth2 source: well-known/underdog-openid-configuration.json flows: - flow: authorizationCode authorizationUrl: https://account.underdog.shop/authentication/oauth/authorize tokenUrl: https://account.underdog.shop/authentication/oauth/token scope_count: 4 scopes: - scope: openid description: Standard OpenID Connect scope; requests an ID token identifying the shopper. flows: [authorizationCode] sources: [well-known/underdog-openid-configuration.json] - scope: email description: Releases the shopper's email and email_verified claims. flows: [authorizationCode] sources: [well-known/underdog-openid-configuration.json] - scope: customer-account-api:full description: Full access to the signed-in shopper's own customer account data (orders, addresses, profile) through the customer account API. flows: [authorizationCode] sources: [well-known/underdog-openid-configuration.json] - scope: customer-account-mcp-api:full description: Full access to the signed-in shopper's own customer account data through the customer account MCP transport. flows: [authorizationCode] sources: [well-known/underdog-openid-configuration.json]