we just published an updated proposal for "Auth Scopes", and are interested in your feedback!
this is a mechanism for OAuth clients to request granular permissions to PDS resources. for example, only write repo records of specific types, or only authenticate to specific remote endpoints