GET /oauth/me; do not ask the user to
enter it.
All requests use the OAuth access token as a Bearer credential:
Endpoints and scopes
These routes use the fullhttps://biq.li/api base URL rather than the
versioned Links API base URL.
Scopes do not replace workspace policy checks. The approving user must still
be a workspace member and allowed to perform the operation.
Create an endpoint
name is required and accepts up to 80 characters. url is required and
accepts up to 2,048 characters. events must contain between one and six
distinct supported event types.
The response returns 201 Created. Copy the signing secret immediately and
store it in a server-side secret manager:
Update or toggle an endpoint
PATCH uses the same name, url, and events payload as creation. Send the
complete desired configuration.
Enable or disable an endpoint separately:
Send a test event
202 Accepted with a pending delivery. Test deliveries
set is_test to true and pass through the same signing and retry pipeline as
production deliveries.
Inspect deliveries
The delivery list acceptsper_page from 10 to 100 and returns page metadata.
The delivery detail includes the request payload, response body, and recorded
attempts. A delivery includes its event ID, event type, status, attempt count,
HTTP status, error message, timestamps, and is_test flag.
URL and ownership rules
- A destination must be a publicly reachable HTTP or HTTPS URL.
- Embedded credentials, localhost, and private or reserved addresses are rejected.
- A workspace cannot register the same normalized URL twice.
- OAuth-created endpoints belong to that OAuth connection.
- Revoking the connection removes the endpoints owned by it.
- An endpoint or delivery from another workspace returns
404.

