> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.simplified.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.simplified.com/_mcp/server.

# Authentication

## Get a key

Create one at **[app.simplified.com/settings/api-keys](https://app.simplified.com/settings/api-keys)**.

> **Note**
>
> The secret is shown **once**, at creation. Copy it then — you cannot retrieve it later,
> only revoke the key and issue a new one.

You can also create keys through the API:

```bash
curl -X POST https://api.simplified.com/api/v1/workspace/api-key \
  -H "Authorization: Api-Key $SIMPLIFIED_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "my integration"}'
```

Keys are scoped to a workspace, and optionally to a single space. One key belongs to one
workspace — to work across workspaces you need a key for each.

## Send it

The key goes in the `Authorization` header. Two prefixes are accepted, and they behave
identically — same key, same user, same workspace and teamspace:

**`Api-Key`**

```bash title="Api-Key"
curl https://api.simplified.com/api/v1/workspaces/current \
  -H "Authorization: Api-Key $SIMPLIFIED_API_KEY"
```

**`Bearer`**

```bash title="Bearer"
curl https://api.simplified.com/api/v1/workspaces/current \
  -H "Authorization: Bearer $SIMPLIFIED_API_KEY"
```

Use whichever your client supports. `Bearer` exists because many HTTP clients, integration
platforms and agent frameworks emit only that scheme and cannot be configured to send a
custom prefix. If yours lets you choose, either is fine.

> **Note**
>
> The key encodes its own workspace, so requests authenticated this way do **not** need an
> `Organization` header. See [Workspaces and spaces](/api-reference/get-started/workspaces-and-spaces).

## Key scoping

A key pinned to a space always operates in that space; sending a conflicting `Space`
header returns `403`. A workspace-scoped key may select a space with the `Space` header,
authorized against your memberships — there is no silent fallback to a default space.

## Errors

| Status | Meaning                                                                                |
| ------ | -------------------------------------------------------------------------------------- |
| `401`  | Missing, malformed, or revoked key — check the `Api-Key` or `Bearer` prefix is present |
| `403`  | Valid key, but no access to the requested workspace or space                           |