There is no scope to misconfigure and no token that quietly covers more than intended: the connection reaches the ecosystem named in its address, full stop. The cost is that a page like this cannot tell you what the tools are, because the endpoint only exists once you have an ecosystem. That trade is a reasonable one for multi-tenant products.
HiveSight's endpoint, addressed per ecosystem: the URL carries the ecosystem id, so each connection is scoped to one by construction.
What that ecosystem exposes. The endpoint is per-account, so there is no shared address to probe and no published tool list.
OAuth 2.1 authorization code with PKCE and dynamic client registration.
Paste a URL, then authorize — add the endpoint to your client, then approve the OAuth consent screen