> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth 2.0 overview

> Reference for Biqli authorization-code connections and workspace-scoped access tokens.

Biqli implements the OAuth 2.0 authorization-code flow for self-service OAuth
applications and Biqli-managed integrations. Each approved connection belongs
to one client, one user, one workspace, and one granted scope set.

For a guided implementation, start with
[Build your own integration](/developers/integrations/quickstart).

## Endpoints

| Purpose | Method | URL |
| :- | :- | :- |
| Authorize | `GET` | `https://biq.li/oauth/authorize` |
| Exchange or refresh a token | `POST` | `https://biq.li/api/v1/oauth/token` |
| Inspect the connection | `GET` | `https://biq.li/api/v1/oauth/me` |
| Revoke the connection | `POST` | `https://biq.li/api/v1/oauth/revoke` |

Token requests use `application/x-www-form-urlencoded`. API requests send the
access token through `Authorization: Bearer <ACCESS_TOKEN>`.

## Client types

| Type | Requirement |
| :- | :- |
| Confidential client | Authenticate token and revocation requests with the client ID and client secret. |
| Public client | Enable PKCE, omit the client secret, and use an S256 verifier and challenge. |

An OAuth access token selects its approved workspace automatically. The current
user must retain workspace access and every API request must pass the token's
scope, workspace policy, plan, and quota checks.

## Reference pages

<CardGroup cols={2}>
  <Card title="Authorization request" icon="arrow-up-right-from-square" href="/docs/api-reference/oauth/authorize">
    Build the redirect and handle approval or denial.
  </Card>

  <Card title="Token endpoint" icon="key" href="/docs/api-reference/oauth/token">
    Exchange a code and rotate refresh tokens.
  </Card>

  <Card title="Connected workspace" icon="building" href="/docs/api-reference/oauth/connection">
    Retrieve the user, connection, and workspace identity.
  </Card>

  <Card title="Scopes" icon="shield-check" href="/docs/api-reference/oauth/scopes">
    Request the smallest granular permission set.
  </Card>

  <Card title="Revocation" icon="ban" href="/docs/api-reference/oauth/revoke">
    Invalidate an installation and its tokens.
  </Card>

  <Card title="Errors" icon="circle-exclamation" href="/docs/api-reference/oauth/errors">
    Handle OAuth protocol errors safely.
  </Card>
</CardGroup>
