> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth scopes

> Choose granular permissions for one connected Biqli workspace.

Request the smallest scope set required by the integration. Scopes are
space-separated in the authorization URL and returned in the token response.

`workspace.read` identifies the connected user and workspace. Resource scopes
grant only the named operation:

| Resource | View | Create | Update | Delete |
| :- | :- | :- | :- | :- |
| Links | `links.view` | `links.create` | `links.update` | `links.delete` |
| QR codes | `qr_codes.view` | `qr_codes.create` | `qr_codes.update` | `qr_codes.delete` |
| Biolinks | `biolinks.view` | `biolinks.create` | `biolinks.update` | `biolinks.delete` |
| Folders | `link_groups.view` | `link_groups.create` | `link_groups.update` | `link_groups.delete` |
| Tracking pixels | `tracking_pixels.view` | `tracking_pixels.create` | `tracking_pixels.update` | `tracking_pixels.delete` |
| Custom domains | `custom_domains.view` | `custom_domains.create` | `custom_domains.update` | `custom_domains.delete` |
| Tags | `tags.view` | `tags.create` | `tags.update` | `tags.delete` |
| Webhook endpoints | `webhooks.view` | `webhooks.create` | `webhooks.update` | `webhooks.delete` |

`conversions.create` records attributed lead and sale events.

## Referenced resources

Creating or updating one resource can require view access to a referenced
resource. For example, creating a link with a custom domain, folder, tag, or
tracking pixel requires `links.create` plus the corresponding resource's view
scope.

## Compatibility scopes

Biqli-managed automation clients can use these broader compatibility scopes:

| Scope | Mapped access |
| :- | :- |
| `links.read` | `links.view` |
| `links.write` | Link view/create/update/delete plus view access to referenced domains, folders, tags, and pixels |
| `webhooks.read` | Read representative webhook event payloads |
| `webhooks.write` | Create and remove managed webhook subscriptions |
| `conversions.write` | `conversions.create` |

New self-service integrations should use granular scopes so the consent screen
describes access precisely.

See [Manage webhook endpoints](/docs/api-reference/webhooks/manage) for the
routes protected by the granular webhook scopes.

Scopes never bypass the approving user's current workspace role, resource
policy, plan entitlement, or quota. A valid token returns `403` with the missing
permission when an operation exceeds its granted access.
