Authentication
Get a key
Create one at app.simplified.com/settings/api-keys.
The secret is shown once, at creation. Copy it then — you cannot retrieve it later, only revoke the key and issue a new one.
You can also create keys through the API:
Keys are scoped to a workspace, and optionally to a single space. One key belongs to one workspace — to work across workspaces you need a key for each.
Send it
The key goes in the Authorization header. Two prefixes are accepted, and they behave
identically — same key, same user, same workspace and teamspace:
Use whichever your client supports. Bearer exists because many HTTP clients, integration
platforms and agent frameworks emit only that scheme and cannot be configured to send a
custom prefix. If yours lets you choose, either is fine.
The key encodes its own workspace, so requests authenticated this way do not need an
Organization header. See Workspaces and spaces.
Key scoping
A key pinned to a space always operates in that space; sending a conflicting Space
header returns 403. A workspace-scoped key may select a space with the Space header,
authorized against your memberships — there is no silent fallback to a default space.
