Tom requests a token through the Token API as grant_type=password&username=nuwantom&password=xxxx&scope=news_read news_write. However, as Tom is not in the manager role, he will only be granted a token bearing the news_read scope. The response from the Token API will be similar to the following: