Skip to navigation

Authentication

Choose OAuth or an API key and verify the account in use.
View as Markdown

Sign in with OAuth

OAuth is the simplest option for an interactive client that supports it. Add the hosted connector, follow the client’s authentication prompt, and sign in to Simplified. Your client manages the resulting session; reconnect if it can no longer refresh authorization.

After signing in, ask the assistant to call api_getWorkspaceInfo. Check the returned user and workspace before creating content.

Connect with an API key

  1. Open Settings → Simplified API.
  2. Create a key in the workspace you want to use and copy the secret when it is shown.
  3. Configure your client’s request header:
Authorization: Bearer YOUR_API_KEY

Use Bearer for MCP. Keep the key out of prompts, screenshots, and committed configuration.

For Codex, reference an environment variable instead of embedding the key in the server entry:

codex mcp add simplified --url https://apikit.simplified.com/mcp --bearer-token-env-var SIMPLIFIED_API_KEY

Set SIMPLIFIED_API_KEY securely in the environment that launches Codex. A GUI application may not inherit variables from your terminal.

Clients that support headers in JSON can use this shape. This placeholder must be replaced through the client’s supported secret configuration:

{
"mcpServers": {
"simplified": {
"url": "https://apikit.simplified.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}

A key authenticates to its associated workspace. Sharing a connector configured with a key shares that credential’s access; it does not create separate user identities.

Change authentication methods

Inspect the existing server entry first. Update or remove only the Simplified entry in the scope where it was configured, then reconnect using the new method. A plugin-managed connection may need to be changed through the plugin’s settings.

Do not create overlapping entries with the same name or delete unrelated client configuration. Verify the new identity with api_getWorkspaceInfo. If a key has been exposed, revoke it and replace it in each client that used it.