Token scope defines capability
What a token can do is decided by its scope, not by who requested it.
A token issued to a trusted application with broad scope is a broad capability in whoever's hands it ends up. Requesting the narrowest scope that works limits the damage of theft, and it is the single most effective thing an integration can do about tokens it cannot fully protect.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
- Token audience prevents universal reuseA ticket for this gate only
