The bearer tokens should support scoping at creation time to limit the token's permission just to certain actions.