Skip to main content
OAuth applications let another product ask a Biqli user for scoped access to one workspace. Create an application for software you operate or distribute; do not create one simply to automate your own workspace from a trusted server. Use a workspace API key for that case.

Create an application

  1. Open Workspace settings → OAuth Apps.
  2. Select Create OAuth app.
  3. Add the application name, slug, description, overview, developer name, and website.
  4. Add the URL where users can begin installing the integration.
  5. Register every exact callback URL used after authorization.
  6. Enable Allow PKCE when the application runs in a browser, mobile app, or desktop client that cannot protect a secret.
  7. Add an icon and optional screenshots, then create the application.
Uploaded media remains staged until you select Create OAuth app or Save changes. Leaving the page without saving does not publish staged changes.

Callback URLs

Callback URLs must match the authorization request exactly, including scheme, hostname, port, path, and trailing slash.
  • Use HTTPS in production.
  • HTTP is accepted only for localhost and loopback development.
  • Add each development, staging, and production callback separately.
  • Remove callback URLs that are no longer deployed.
Biqli rejects authorization when the supplied callback is not registered.

Client ID and secret

The application details page shows the client ID. Creating an application does not reveal its initial client secret. When a confidential server application is ready to connect, open the application menu and select Regenerate secret. The new secret is shown once. Copy it directly into a server-side secret manager. Regenerating the secret invalidates the previous client secret, so deploy the replacement deliberately. Public clients use S256 PKCE and must not receive a client secret.

Edit the application listing

Open an application and select Configuration to change its listing, callback URLs, media, or PKCE setting. The save action remains disabled until the page differs from the saved application. Saving shows a confirmation and keeps you on the configuration page. The name, developer, icon, description, requested permissions, and verification status can appear on the authorization screen. Write them for users who need to decide whether they trust the connection.

Remove an application

Removing an OAuth application:
  • prevents new authorization requests;
  • revokes every active connection created by that application;
  • invalidates its access and refresh tokens;
  • removes webhook endpoints owned by those OAuth connections; and
  • deletes the application’s uploaded icon and screenshots.
It does not delete ordinary links or other workspace resources previously created through the integration.

Continue building

Read Build your own integration for the authorization flow, token lifecycle, scopes, and production checklist.