Skip to navigation

Authentication

Workspace API keys, sent as an Authorization header.
View as Markdown

Get a key

Create one at app.simplified.com/settings/api-keys.

The secret is shown once, at creation. Copy it then — you cannot retrieve it later, only revoke the key and issue a new one.

You can also create keys through the API:

curl -X POST https://api.simplified.com/api/v1/workspace/api-key \
-H "Authorization: Api-Key $SIMPLIFIED_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "my integration"}'

Keys are scoped to a workspace, and optionally to a single space. One key belongs to one workspace — to work across workspaces you need a key for each.

Send it

The key goes in the Authorization header. Two prefixes are accepted, and they behave identically — same key, same user, same workspace and teamspace:

curl https://api.simplified.com/api/v1/workspaces/current \
-H "Authorization: Api-Key $SIMPLIFIED_API_KEY"

Use whichever your client supports. Bearer exists because many HTTP clients, integration platforms and agent frameworks emit only that scheme and cannot be configured to send a custom prefix. If yours lets you choose, either is fine.

The key encodes its own workspace, so requests authenticated this way do not need an Organization header. See Workspaces and spaces.

Key scoping

A key pinned to a space always operates in that space; sending a conflicting Space header returns 403. A workspace-scoped key may select a space with the Space header, authorized against your memberships — there is no silent fallback to a default space.

Errors

StatusMeaning
401Missing, malformed, or revoked key — check the Api-Key or Bearer prefix is present
403Valid key, but no access to the requested workspace or space