quote:read; payment creation and tracking use settlement
scopes; recipient tools use read or write scopes; wallet execution uses
agent_wallet:use; revocation uses agent:revoke.
Use check_my_scopes as a diagnostic, but note that its displayed map may still
contain legacy compatibility entries even when backend enforcement is correct.
Hosted OAuth grants connection-specific scopes and exposes a different tool
surface. Use check_my_scopes and the live tool list rather than applying the
local onboarding scope list to a hosted connection.
