Once you select any group you will get the all API categories. Users can select the APIs to give/take permissions in that particular group of API users.
If the user checks the checkbox in the header all the checkboxes are checked for that box column.
The application user(end-user) has to send a token of the API user in the token-required APIs. The application user can access only the APIs which have access permission to that API user.