Authentication
Connect to https://mcp.shippdf.com using either a workspace API token or OAuth. Both authenticate your assistant’s requests; the granted scopes decide which tools it can use.
| Method | Use it when |
|---|---|
| Authorization header | Your client accepts a bearer token or custom HTTP headers. |
| OAuth | Your client supports browser sign-in to a remote MCP server. |
Use an Authorization header
Create a workspace API token under Members & keys. The API authentication guide walks through key creation. Choose the scopes and resource access your assistant needs from Capabilities and permissions.
Configure your MCP client with the server URL and this header:
Authorization: Bearer spdf_xxx
Replace spdf_xxx with your token. The same workspace token works with the REST API and MCP. Store it in your client’s secret configuration or environment, and keep it out of prompts and source control.
Use OAuth
Add the remote server URL to your client and choose OAuth. Your client discovers ShipPDF’s authorization server and opens the sign-in flow. Sign in to ShipPDF, select a workspace, review the requested permissions, and approve the connection.
You need permission to manage API tokens in the workspace you select. OAuth connections have workspace-wide resource access within their granted scopes. For access restricted to particular resources, use an API token configured with those restrictions.
ShipPDF supports authorization code flow with PKCE (S256), Client ID Metadata Documents, and dynamic client registration. Clients can discover the configuration at:
https://mcp.shippdf.com/.well-known/oauth-protected-resource
Access tokens last one hour. Clients can renew them using rotating refresh tokens, whose lifetime is 90 days. If renewal fails, sign in again. To revoke a connection, open Members & keys → Connected applications in ShipPDF and remove the app.
OAuth supports the five named MCP scopes in the permissions table. It does not support the API token wildcard * or webhooks:manage. When a client omits scopes, ShipPDF requests all five MCP scopes; review the consent screen before approving.
Connect your client
ChatGPT
- Enable Developer mode in Settings → Security and login, if available to your account.
- Open Plugins and create a developer-mode app named ShipPDF.
- Enter
https://mcp.shippdf.comand select OAuth. Use automatic client discovery rather than supplying static credentials. - Complete ShipPDF sign-in, then select the app in your conversation’s Developer mode menu.
Availability depends on your account and workspace settings. See OpenAI’s developer mode guide for current setup details.
Claude Desktop
- Open Customize → Connectors, choose + Add → Add custom connector, and name it ShipPDF.
- Enter
https://mcp.shippdf.comand continue. - Review the detected authentication settings, choose Sign in now, and complete ShipPDF authorization.
- Enable the connector for your conversation.
Workspace policies may control who can add connectors. See Claude’s remote connector guide.
Codex
For OAuth, add the remote server and sign in:
codex mcp add shippdf --url https://mcp.shippdf.com
codex mcp login shippdf
For an API token, add this to ~/.codex/config.toml instead:
[mcp_servers.shippdf]
url = "https://mcp.shippdf.com"
bearer_token_env_var = "SHIPPDF_API_TOKEN"
Set SHIPPDF_API_TOKEN in the environment that launches Codex. Use /mcp in the CLI to inspect the connection. See OpenAI’s MCP configuration guide.
Clients that only support stdio
Use mcp-remote to bridge a local stdio connection to ShipPDF. With Node.js installed, add this to your client’s MCP configuration:
{
"mcpServers": {
"shippdf": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://mcp.shippdf.com",
"--header",
"Authorization:${SHIPPDF_AUTH_HEADER}"
],
"env": {
"SHIPPDF_AUTH_HEADER": "Bearer spdf_xxx"
}
}
}
}
Replace the placeholder token and restart your client if it requires a restart to load configuration changes.
Verify the connection
With templates:read granted, ask:
Use ShipPDF to list the published templates I can access.
An empty list can mean there are no published templates within your connection’s resource access. If the tool is missing, check the granted scopes and refresh your client’s tool list. For authentication failures, see Limits and errors.
Next: Capabilities and permissions.