Currently, all REST interfaces use hardcoded scope values to verify that a user is allowed to access a particular interface. It might be a good idea to make these values configurable and allow the deployer to specify custom (e.g. namespaced) values.