This page documents the Biqli-managed client and endpoints used by the
official Make app. To connect your own product directly, create a
self-service OAuth app and request only the
granular scopes it needs.
Connection flow
When you create a Biqli connection in Make, Make redirects you to Biqli. Sign in, select one workspace, and approve the requested permissions. Biqli then returns you to Make through the exact registered callback URL.
The authorization request includes:
The user must own the selected workspace or have the workspace permissions
required by the requested scopes. Workspace roles, product entitlements,
quotas, and resource ownership continue to apply after OAuth approval.
Connect from Make
Authorized pre-release testers will connect the app from a Make scenario:- Add any Biqli module and select Create a connection.
- Continue to Biqli, sign in, and select the intended workspace.
- Review and approve the requested permissions.
- Return to Make and confirm the connection label shows the selected workspace.
- Use a separate Make connection when a scenario needs another workspace.
Permissions requested by Make
Token exchange and refresh
Make exchanges the single-use authorization code through a confidential, server-to-server request. The client secret never passes through the browser.Test or revoke the connection
Make validates and labels the connection with:Instant triggers
The planned app will provide these instant triggers:
Each module uses a dedicated attached webhook. When you activate a trigger,
Make creates a unique receiver URL and registers it with Biqli. When you remove
the trigger, Make detaches that exact subscription.
Attach a webhook
id with its webhook component and uses it when the
trigger is detached. Biqli accepts only public HTTP or HTTPS destinations. It
rejects private, loopback, link-local, reserved, credential-bearing, and
unresolvable targets. A target URL can have only one subscription in a
workspace.
Detach a webhook
Load representative trigger data
id.
Action modules
The planned app will expose these workspace-scoped actions:
The OAuth connection selects the workspace. Requests never accept an internal
workspace database ID. Link IDs outside the connected workspace return
404
without revealing whether the resource exists.
Link actions
Create a Link requireslong_url. It returns the complete link under
link. A synchronously accepted link returns 201; a link waiting for an
asynchronous safety scan returns 202 with status: "pending".
Update a Link is a partial update. Omitted fields remain unchanged. Send
JSON null only for nullable fields supported by the canonical update contract.
Upsert a link
Upsert requiresexternal_id and long_url. Biqli updates the workspace link
with that external ID when it exists, or creates it when it does not. The
response includes operation: "updated" or operation: "created".
biq_lnk_... ID and runs the same cleanup,
activity logging, and link.deleted event behavior as a dashboard deletion.
Conversion actions
Track Lead and Track Sale use Biqli’s canonical attribution, validation, currency, and durable idempotency paths. Conversion tracking must be enabled in the connected workspace. Send a stableIdempotency-Key on every retry. Track Lead also requires a
stable eventId. Track Sale requires a stable invoiceId and can also receive
eventId. Reusing an idempotency identity with the identical validated payload
returns the stored response and sets Idempotency-Replayed: true. Reusing it
with different data returns 409 idempotency_conflict.
1299 means
$12.99 USD.
Make an API Call
The planned app includes one universal Make an API Call module. It accepts only paths relative tohttps://biq.li; it cannot send the OAuth token
to another host. The pre-release module allowlists /api/v1/oauth/me and the
/api/v1/integrations/make/* namespace, rejects parent-directory segments,
and still enforces the connection’s OAuth scopes and workspace permissions.
Errors
OAuth errors contain
error and error_description. Workspace API errors
contain error.code, error.message, and request_id. Validation details are
included when available.
Troubleshooting
When contacting support, include the request ID and UTC time. Never send an
access token, refresh token, authorization code, client secret, or full Make
webhook URL.

