100 Thieves · OAuth Scopes

100 Thieves OAuth Scopes

OAuth 2.0 probed

100 Thieves publishes 4 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the 100 Thieves API on a user’s behalf.

Tokens are issued from https://shopify.com/authentication/31052262/oauth/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CompanyEsportsGamingApparelRetailE-CommerceEntertainmentMediaDirect To ConsumerAgentic Commerce
Scopes: 4 Flows: authorizationCode Method: probed

OAuth endpoints

Authorization URL
https://shopify.com/authentication/31052262/oauth/authorize
Token URL
https://shopify.com/authentication/31052262/oauth/token
Flows
authorizationCode

Scopes (4)

ScopeDescriptionFlows
openid Standard OpenID Connect scope — requests an ID token for the signed-in customer. authorizationCode
email Releases the customer's email and email_verified claims. authorizationCode
customer-account-api:full Full access to the Shopify Customer Account API on behalf of the signed-in customer — orders, addresses, profile. authorizationCode
customer-account-mcp-api:full Full access to the customer-scoped MCP API on behalf of the signed-in customer. Distinct from the anonymous UCP shopping MCP endpoint at /api/ucp/mcp, which needs no token. authorizationCode

Source

OAuth Scopes

100-thieves-scopes.yml Raw ↑
generated: '2026-08-05'
method: probed
source: https://100thieves.com/.well-known/openid-configuration
note: >-
  No OpenAPI exists, so derive-oauth-scopes.py found nothing. These scopes are read
  verbatim from the scopes_supported array of the live OIDC/OAuth discovery documents
  served on the 100 Thieves host by Shopify Customer Accounts. Descriptions are ours;
  the scope strings are the provider's.
schemes:
- name: shopify-customer-accounts
  source: https://100thieves.com/.well-known/openid-configuration
  issuer: https://shopify.com/authentication/31052262
  flows:
  - flow: authorizationCode
    authorizationUrl: https://shopify.com/authentication/31052262/oauth/authorize
    tokenUrl: https://shopify.com/authentication/31052262/oauth/token
    pkce: S256
scopes:
- scope: openid
  description: Standard OpenID Connect scope — requests an ID token for the signed-in
    customer.
  flows: [authorizationCode]
  sources: [well-known/100-thieves-openid-configuration.json]
- scope: email
  description: Releases the customer's email and email_verified claims.
  flows: [authorizationCode]
  sources: [well-known/100-thieves-openid-configuration.json]
- scope: customer-account-api:full
  description: Full access to the Shopify Customer Account API on behalf of the signed-in
    customer — orders, addresses, profile.
  flows: [authorizationCode]
  sources: [well-known/100-thieves-openid-configuration.json]
- scope: customer-account-mcp-api:full
  description: Full access to the customer-scoped MCP API on behalf of the signed-in
    customer. Distinct from the anonymous UCP shopping MCP endpoint at /api/ucp/mcp,
    which needs no token.
  flows: [authorizationCode]
  sources: [well-known/100-thieves-openid-configuration.json]
coverage:
  scopes_total: 4
  documented_by_provider: false
  note: 100 Thieves publishes no scopes reference page of its own; the scope list is
    machine-readable only, via the discovery document.
x-evidence:
- url: https://100thieves.com/.well-known/openid-configuration
  http_status: 200
  content_type: application/json