The UMA group that's been working on this is considering how to incorporate these detailed elements into broader declaration formats such as Swagger. Currently the info gets actively registered by a resource server at an authorization server. If you have questions on this, let me know (I chair that group).
There's an effort to standardize how to declare access control scopes and protected resource sets at a fairly deep level, here:
http://tools.ietf.org/html/draft-hardjono-oauth-resource-reg-02
The UMA group that's been working on this is considering how to incorporate these detailed elements into broader declaration formats such as Swagger. Currently the info gets actively registered by a resource server at an authorization server. If you have questions on this, let me know (I chair that group).
From Eve Maler - https://groups.google.com/forum/#!topic/apisjson/s30XLjP8Q0A