# App Permissions

- App creation uses access checkpoints instead of a raw scope-only textarea.
- Common permissions are grouped in the UI, and advanced custom scopes remain available for future Anan platform capabilities.
- The server payload still persists `allowedScopes: string[]` for OAuth mirror compatibility.