Integrations and automation

Simplist is usable from a script, from an AI agent, and offline on your phone — and it can pull data in on a schedule without you doing anything. All four use the same records you already have.

API keys

Create a personal API key under Account → API keys. The full sk_… secret is shown once, at creation, so copy it then.

By default a key has the same access your account has, but you can narrow it when you create it:

Revoke a key at any time from the same page.

The REST API

Send Authorization: Bearer sk_… on any /api/… route. The key stands in for the browser session, and key-authenticated requests skip the CSRF round-trip, so a script needs no cookie handling.

Pick a workspace with an x-simplist-workspace header; omit it to use your default workspace.

curl https://your-simplist-instance/api/models \
  -H "Authorization: Bearer sk_…" \
  -H "x-simplist-workspace: <workspace-uuid>"

An interactive reference for the whole surface is published in the app at /api-docs, and the OpenAPI specification behind it is served at /api/openapi.json — fetch it with your key to feed Postman, a code generator, or any other OpenAPI tool.

One exception: changing your password refuses key authentication, because it revokes every other session and that is meaningless without one. Change your password in the web app.

AI agents (MCP)

Simplist is its own MCP server, so an agent like Claude can create models, write documents and manage files on your behalf. The same sk_… key works as a bearer token, or you can connect through the OAuth flow.

Either way, the connection can be made read-only. Connecting through OAuth, choose Read-only under Access on the approval page; with a key, create it as Read-only. A read-only connection only sees the tools that list, search and read, and every write is refused. Whatever you choose, a connection never gets more than your own role in the workspace allows. An MCP client that only asks for read access (the mcp:read scope) is shown as read-only on the approval page, and you cannot widen it.

Keeping an agent’s changes safe

Everything an agent writes is labelled with the key or app it used, in a record’s history and in the activity feed. The Agents page (in the sidebar) shows each agent session, meaning each connection that changed something, with what it touched.

A key with any of these limits can still read through the REST API, but it can only make changes through MCP, where the limits are enforced.

What agents are told about your workspace

When an agent connects, Simplist gives it a briefing: your models and what they are for, what belongs in each field, how often each field is filled in and its usual values, how models link, a couple of recent records written by people, and any changes you recently rejected. It is built from your workspace each time, and you can read exactly the same text under Agents → Briefing.

The in-app reference at /mcp-docs lists the available tools and how to connect.

Connectors

A connector is a standing instruction that turns something outside the app into documents of a model you choose. Three kinds ship today:

Set one up at Connectors: name it, pick the model it files into, and point each thing the source produces at one of your fields. That mapping is the connector. It decides nothing on its own — it repeats a choice you already made, with no AI involved.

Attributes are mapped by kind, so a calendar’s start time is only offered your date fields and cannot be filed into a text field where it would look right and sort wrong.

Some consequences worth knowing:

Working offline

Simplist is an installable progressive web app. You can browse, create, edit and delete records — and change your models — with no connection, and it syncs when you are back online. A small badge marks anything not yet saved to the server.

Conflicts are never resolved silently. If someone changed a record while you were offline, /sync holds it for an explicit decision: keep yours, or discard it.

Outbound webhooks

Any workspace, on any plan, can register endpoint URLs that receive a signed POST when a document is created, updated or deleted — for wiring Simplist into something else you run. Configure them under Workspace settings → Webhooks; each endpoint gets a signing secret, shown once.

Every POST carries an X-Simplist-Delivery header. A delivery that fails is retried, and each retry of the same event carries the same value, so store the ids you have handled and ignore one you have seen before.