The authorization fragment's relations section: one entry per object type.
Display name.
OptionalfeaturesFeature keys (<key>.<name>) the app asks about; any other key is refused.
The app key (^[a-z][a-z0-9_]{1,31}$); its object types and features are namespaced by it.
The service client whose token identifies the app's backend.
The app's version, for the catalog.
What an app registers: its key, service client, feature keys and object types.