scope
parameter to specify what access it needs, and the authorization server uses the scope
parameter to respond with the access that was actually granted (if the granted access was different from what was requested).
Generally, you use scopes in three ways: