Token scope defines capability

What a token can do is decided by its scope, not by who requested it.

A token issued to a trusted application with broad scope is a broad capability in whoever's hands it ends up. Requesting the narrowest scope that works limits the damage of theft, and it is the single most effective thing an integration can do about tokens it cannot fully protect.

More on OAuth and federation