Skip to main content
OAuth integrations can manage webhook endpoints in the workspace selected during authorization. Use the workspace public ID returned by GET /oauth/me; do not ask the user to enter it. All requests use the OAuth access token as a Bearer credential:

Endpoints and scopes

These routes use the full https://biq.li/api base URL rather than the versioned Links API base URL. Scopes do not replace workspace policy checks. The approving user must still be a workspace member and allowed to perform the operation.

Create an endpoint

name is required and accepts up to 80 characters. url is required and accepts up to 2,048 characters. events must contain between one and six distinct supported event types. The response returns 201 Created. Copy the signing secret immediately and store it in a server-side secret manager:
The secret is included only when the caller can configure the endpoint. Treat it like a password. Use it to verify every delivery.

Update or toggle an endpoint

PATCH uses the same name, url, and events payload as creation. Send the complete desired configuration. Enable or disable an endpoint separately:
Disabling an endpoint stops new production events. It does not remove delivery history, and test deliveries remain available for diagnosis.

Send a test event

The endpoint returns 202 Accepted with a pending delivery. Test deliveries set is_test to true and pass through the same signing and retry pipeline as production deliveries.

Inspect deliveries

The delivery list accepts per_page from 10 to 100 and returns page metadata. The delivery detail includes the request payload, response body, and recorded attempts. A delivery includes its event ID, event type, status, attempt count, HTTP status, error message, timestamps, and is_test flag.

URL and ownership rules

  • A destination must be a publicly reachable HTTP or HTTPS URL.
  • Embedded credentials, localhost, and private or reserved addresses are rejected.
  • A workspace cannot register the same normalized URL twice.
  • OAuth-created endpoints belong to that OAuth connection.
  • Revoking the connection removes the endpoints owned by it.
  • An endpoint or delivery from another workspace returns 404.
For event envelopes, signature verification, retries, and receiver behavior, continue with the Webhooks guide.