Problem API and OAuth tokens currently have very wide permissions across all resources, such as the 'Shared Resources' scope allowing read+write access to all shared resources. Request Support more granular scopes for API tokens and OAuth tokens, ...