Skip to main content
Biqli implements the OAuth 2.0 authorization-code flow for self-service OAuth applications and Biqli-managed integrations. Each approved connection belongs to one client, one user, one workspace, and one granted scope set. For a guided implementation, start with Build your own integration.

Endpoints

Token requests use application/x-www-form-urlencoded. API requests send the access token through Authorization: Bearer <ACCESS_TOKEN>.

Client types

An OAuth access token selects its approved workspace automatically. The current user must retain workspace access and every API request must pass the token’s scope, workspace policy, plan, and quota checks.

Reference pages

Authorization request

Build the redirect and handle approval or denial.

Token endpoint

Exchange a code and rotate refresh tokens.

Connected workspace

Retrieve the user, connection, and workspace identity.

Scopes

Request the smallest granular permission set.

Revocation

Invalidate an installation and its tokens.

Errors

Handle OAuth protocol errors safely.