# Jhilke Studio auth.md

Who this is for: AI agents shopping or asking questions on behalf of a person.

## Registration

There is none. Agents do not register or receive credentials from Jhilke Studio.

## What needs credentials

- **Shop MCP server** (https://jhilkestudio.com/api/ucp/mcp): browsing, product data, carts and starting a checkout need no credentials. Completing a checkout needs the buyer's explicit approval of the payment, given at that moment. See https://jhilkestudio.com/agents.md.
- **Storefront API** (https://jhilkestudio.com/openapi.json): products, search and the cart need no credentials; the cart is kept in Shopify's "cart" cookie. The buyer pays in Shopify's checkout, never through the API.
- **Store assistant** (A2A, https://jhilke-ai.zeabur.app/a2a): no credentials. Rate limited per IP.
- **Customer accounts**: a buyer signs in to their own account with Shopify customer accounts (OAuth 2.0 and OpenID Connect, run by Shopify). Protected resource metadata: https://jhilkestudio.com/.well-known/oauth-protected-resource. OpenID configuration: https://jhilkestudio.com/.well-known/openid-configuration. Agents never handle a buyer's password.

## Contact

Partners and agent builders: https://jhilkestudio.com/pages/contact
