workspace.read identifies the connected user and workspace. Resource scopes
grant only the named operation:
conversions.create records attributed lead and sale events.
Referenced resources
Creating or updating one resource can require view access to a referenced resource. For example, creating a link with a custom domain, folder, tag, or tracking pixel requireslinks.create plus the corresponding resource’s view
scope.
Compatibility scopes
Biqli-managed automation clients can use these broader compatibility scopes:
New self-service integrations should use granular scopes so the consent screen
describes access precisely.
See Manage webhook endpoints for the
routes protected by the granular webhook scopes.
Scopes never bypass the approving user’s current workspace role, resource
policy, plan entitlement, or quota. A valid token returns
403 with the missing
permission when an operation exceeds its granted access.
