Skip to main content
The authorization endpoint signs the user in, displays the requested permissions, and lets the user choose one accessible workspace.

Query parameters

Self-service applications must explicitly request at least one scope. The requested set must be supported by Biqli and allowed for that client.

Successful authorization

Biqli redirects to the registered callback URL:
Verify state before using the code. The code expires after five minutes, is bound to the client, callback URL, user, workspace, scopes, and optional PKCE challenge, and can be exchanged only once.

Denied authorization

When the user declines, Biqli redirects with: Do not exchange a code unless the returned state matches the value stored for the initiating browser session.