Hmm, maybe. It's not in response to resource registration but rather resource request (client) --> permission request (RS, formal in the case of FedAuthz or informal if FedAuthz isn't being used). That's why the wording was fuzzed. Also, "exchange" isn't right because it's not a one-for-one swap as if it were an authorization code. (I also notice that we left out saying "correlation handle for requested permissions".)
How about this instead? It's a bit detailed, but does explain in words what people are seeing in the swimlane, does mention all three entities, and rectifies the problem with not mentioning what the handle correlates. :-) (I would then also move this definition after the definition for "permission".)
"A correlation handle representing requested permissions that is created and maintained by the authorization server, initially passed to the client by the resource server, and presented by the client at the token endpoint and during requesting party redirects."