> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.simplified.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.simplified.com/_mcp/server.

# Authentication

## Sign in with OAuth

OAuth is the simplest option for an interactive client that supports it. Add the [hosted connector](/mcp/connect-your-client), follow the client's authentication prompt, and sign in to Simplified. Your client manages the resulting session; reconnect if it can no longer refresh authorization.

After signing in, ask the assistant to call `api_getWorkspaceInfo`. Check the returned user and workspace before creating content.

## Connect with an API key

1. Open [Settings → Simplified API](https://app.simplified.com/settings/api-keys).
2. Create a key in the workspace you want to use and copy the secret when it is shown.
3. Configure your client's request header:

```text
Authorization: Bearer YOUR_API_KEY
```

Use **Bearer** for MCP. Keep the key out of prompts, screenshots, and committed configuration.

For Codex, reference an environment variable instead of embedding the key in the server entry:

```bash
codex mcp add simplified --url https://apikit.simplified.com/mcp   --bearer-token-env-var SIMPLIFIED_API_KEY
```

Set `SIMPLIFIED_API_KEY` securely in the environment that launches Codex. A GUI application may not inherit variables from your terminal.

Clients that support headers in JSON can use this shape. This placeholder must be replaced through the client's supported secret configuration:

```json
{
  "mcpServers": {
    "simplified": {
      "url": "https://apikit.simplified.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}
```

A key authenticates to its associated workspace. Sharing a connector configured with a key shares that credential's access; it does not create separate user identities.

## Change authentication methods

Inspect the existing server entry first. Update or remove only the Simplified entry in the scope where it was configured, then reconnect using the new method. A plugin-managed connection may need to be changed through the plugin's settings.

Do not create overlapping entries with the same name or delete unrelated client configuration. Verify the new identity with `api_getWorkspaceInfo`. If a key has been exposed, revoke it and replace it in each client that used it.