Glossary
OAuth scope
A named permission an app requests on a Google account, such as reading Gmail or all of Drive; the scope list defines what a token can do.
An OAuth scope is a named permission that an application requests when a user (or an admin) authorizes it. Examples: https://mail.google.com/ (full Gmail access), https://www.googleapis.com/auth/gmail.readonly, …/drive (all Drive files), …/drive.file (only files the app created).
The scope list is the most important field of an OAuth token log authorize event. It tells you what an app can read, send or change. Gmail-wide, Drive-wide and admin scopes deserve review. Sign-in scopes (openid, userinfo.email) don't.
See: illicit consent grant and suspicious OAuth apps.