Invite link builder
Tick what your bot needs. The link and its permissions number update as you go.
On the Developer Portal: your application, General Information, Application ID. It is not secret.
Administrator gives the bot every permission in every server it joins. If its token ever leaks, so does all of that. Tick only what it uses.
Permissions number 0
Invite link Type the application ID first
What this makes
A bot joins a server through an invite link that names the bot (its application ID), what it asks for (the bot and applications.commands scopes) and the permissions it wants, as one number. Each permission is one bit of that number; the number is all of them added up. Whoever adds the bot sees the list and can untick any of them.
Ask for less
Most bots need View Channels, Send Messages, Embed Links and Read Message History, and nothing else. Slash commands need no permission at all: the applications.commands scope covers them. A bot that asks for Administrator gets added to fewer servers, and a leaked token for it is a disaster rather than a nuisance.
Changing them later
Permissions are given when the bot is added. To change them, a server admin edits the bot's role in Server Settings, Roles, or kicks the bot and adds it again with a new link.