OAUTH Token request/response not sending scopes

Hi,

Is there any RBAC enabled?
What’s the request look like, and what’s the token returned (as decoded)?

If possible, could you share a HAR file? Remember to redact the password, client ID/secret and other sensitive informations.