OAuth scopes

Scopes describe what an application may do on somebody's behalf, and they are only meaningful if they are narrow.

An application granted broad read and write access has the user's authority for everything, which is what makes consent phishing profitable. Requesting the minimum, and services defining scopes fine-grained enough to make that possible, is what turns the model into a real constraint.

Checked against the primary source.

More on API security