Skip to main content
Request the smallest scope set required by the integration. Scopes are space-separated in the authorization URL and returned in the token response. workspace.read identifies the connected user and workspace. Resource scopes grant only the named operation: conversions.create records attributed lead and sale events.

Referenced resources

Creating or updating one resource can require view access to a referenced resource. For example, creating a link with a custom domain, folder, tag, or tracking pixel requires links.create plus the corresponding resource’s view scope.

Compatibility scopes

Biqli-managed automation clients can use these broader compatibility scopes: New self-service integrations should use granular scopes so the consent screen describes access precisely. See Manage webhook endpoints for the routes protected by the granular webhook scopes. Scopes never bypass the approving user’s current workspace role, resource policy, plan entitlement, or quota. A valid token returns 403 with the missing permission when an operation exceeds its granted access.