# La Epic auth.md

La Epic exposes public catalog discovery through UCP and MCP. Read-only catalog tools require no merchant-issued credential.

## Public resources

- Resource: `https://www.laepic.es`
- OAuth Protected Resource Metadata: `https://www.laepic.es/.well-known/oauth-protected-resource`
- OpenID Connect metadata: `https://www.laepic.es/.well-known/openid-configuration`
- UCP profile: `https://www.laepic.es/.well-known/ucp`
- MCP endpoint: `https://www.laepic.es/api/ucp/mcp`

## Authentication

Customer-specific account, checkout, and order operations use Shopify's published OAuth and buyer-approval flows. Agents must discover the supported authorization servers and scopes from the well-known metadata above. La Epic does not operate a separate autonomous-agent registration endpoint and does not issue bespoke agent credentials.

Payment and order completion require explicit, contemporaneous buyer approval.
