> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Create and manage OAuth applications

> Configure the application users see when they connect a Biqli workspace.

OAuth applications let another product ask a Biqli user for scoped access to
one workspace. Create an application for software you operate or distribute;
do not create one simply to automate your own workspace from a trusted server.
Use a workspace API key for that case.

## Create an application

1. Open **Workspace settings → OAuth Apps**.
2. Select **Create OAuth app**.
3. Add the application name, slug, description, overview, developer name, and
   website.
4. Add the URL where users can begin installing the integration.
5. Register every exact callback URL used after authorization.
6. Enable **Allow PKCE** when the application runs in a browser, mobile app, or
   desktop client that cannot protect a secret.
7. Add an icon and optional screenshots, then create the application.

Uploaded media remains staged until you select **Create OAuth app** or
**Save changes**. Leaving the page without saving does not publish staged
changes.

## Callback URLs

Callback URLs must match the authorization request exactly, including scheme,
hostname, port, path, and trailing slash.

* Use HTTPS in production.
* HTTP is accepted only for localhost and loopback development.
* Add each development, staging, and production callback separately.
* Remove callback URLs that are no longer deployed.

Biqli rejects authorization when the supplied callback is not registered.

## Client ID and secret

The application details page shows the client ID. Creating an application does
not reveal its initial client secret. When a confidential server application is
ready to connect, open the application menu and select **Regenerate secret**.

The new secret is shown once. Copy it directly into a server-side secret
manager. Regenerating the secret invalidates the previous client secret, so
deploy the replacement deliberately.

Public clients use S256 PKCE and must not receive a client secret.

## Edit the application listing

Open an application and select **Configuration** to change its listing,
callback URLs, media, or PKCE setting. The save action remains disabled until
the page differs from the saved application. Saving shows a confirmation and
keeps you on the configuration page.

The name, developer, icon, description, requested permissions, and verification
status can appear on the authorization screen. Write them for users who need to
decide whether they trust the connection.

## Remove an application

Removing an OAuth application:

* prevents new authorization requests;
* revokes every active connection created by that application;
* invalidates its access and refresh tokens;
* removes webhook endpoints owned by those OAuth connections; and
* deletes the application's uploaded icon and screenshots.

It does not delete ordinary links or other workspace resources previously
created through the integration.

## Continue building

Read [Build your own integration](/developers/integrations/quickstart) for the
authorization flow, token lifecycle, scopes, and production checklist.
