OAuth sanity check

Looking at the API, it doesent appear as if the new API has anything like the openid from the V5. What do I use instead? Do I just go with something like chat:edit and assume that, because I have edit permissions, it is a logged in user? It makes logical sense, but it feels less secure than specifying openid.