Groups claim assigned in application

Can we include list of groups that is aasigned to application in access token?

No, you cannot, at least not dynamically. The only groups that can be dynamically included into tokens are those to which the requesting user is assigned, not that the requesting client is assigned.

If you want to get this type of information added into your tokens, you could look to use a static allow list as described in this doc.

