1. Pick an endpoint from the left, or type any FHIR path above.
2. The scope checker fires instantly — it shows whether your scope string would permit the call before you send.
3. Edit the scope string to try what happens when you remove a permission.
4. Click Send to fire the (faked) request and see the response.