Fortunately for the User, the Authorization Server can usually find a default set of scopes from somewhere, and usually knows how to render the values in a way that a User will understand (e.g., from Facebook, ???do you allow this application (<URL>) to access your personal data, including email address and photos???).