Starter default
Use this exact default set in your registration request and first authorization:follow:write or like:write separately if your product needs them. For block:read, block:write and report:write, include a justification explaining the safety experience you will provide. Safety scopes are granted on request, rather than included in the default registration.
A capability_required refusal means the current grant lacks the required scope. Update registration if necessary, then obtain deliberate consent for a new grant. Do not silently broaden authority, reuse an old grant, or fall back to anonymous reads.
Anonymous public reads currently need no scope. They may later require an application credential. Application-attributed reads through an application-only credential are a planned follow-up; the client credentials grant is not supported today.