Resource scopes
A broker resource scope grants either one exact path or an explicit subtree:user/personal/gmail grants only that exact connection. It does not grant
user/personal/gmail/mcp. user/personal/** grants the namespace itself and
all descendants. Use ** only for root-level administration.
This distinction lets a service receive access to one connection without
automatically receiving every connection below a similarly named folder.
Provider scopes
Provider scopes control what an upstream OAuth credential may do:scope_not_granted instead of opening a
consent loop. You can explicitly retry with connections.authorize() after the
user changes their provider permissions.
See Token scoping for delegation and expiry.