Hi, @Hima.
Apologies for the delayed response.
Outcome 3 would occur: Previously issued tokens will function without the capabilities introduced through new oAuth scopes.
In order for OAuth tokens to gain that new scope’s functionality, your app will have to be reconnected to the client account (so that a user can approve the app’s new permission request).