Coarse-grained scope in ID token to fine-grained API permission

(For some reason - I asked here - I am unable to put relevant tags on my posts. This one needs rbac, roles, scope, permissions, …)