Can we please have the ability to scope the personal access token to projects? I know that, today, I can scope the MCP access in mcp.json to just a project. However, it would be more secure, and appropriate, to do this at token level.