Docs
EN
Sign up

Authentication

Connect to https://mcp.shippdf.com using either a workspace API token or OAuth. Both authenticate your assistant’s requests; the granted scopes decide which tools it can use.

MethodUse it when
Authorization headerYour client accepts a bearer token or custom HTTP headers.
OAuthYour client supports browser sign-in to a remote MCP server.

Use an Authorization header

Create a workspace API token under Members & keys. The API authentication guide walks through key creation. Choose the scopes and resource access your assistant needs from Capabilities and permissions.

Configure your MCP client with the server URL and this header:

Authorization: Bearer spdf_xxx

Replace spdf_xxx with your token. The same workspace token works with the REST API and MCP. Store it in your client’s secret configuration or environment, and keep it out of prompts and source control.

Use OAuth

Add the remote server URL to your client and choose OAuth. Your client discovers ShipPDF’s authorization server and opens the sign-in flow. Sign in to ShipPDF, select a workspace, review the requested permissions, and approve the connection.

You need permission to manage API tokens in the workspace you select. OAuth connections have workspace-wide resource access within their granted scopes. For access restricted to particular resources, use an API token configured with those restrictions.

ShipPDF supports authorization code flow with PKCE (S256), Client ID Metadata Documents, and dynamic client registration. Clients can discover the configuration at:

https://mcp.shippdf.com/.well-known/oauth-protected-resource

Access tokens last one hour. Clients can renew them using rotating refresh tokens, whose lifetime is 90 days. If renewal fails, sign in again. To revoke a connection, open Members & keys → Connected applications in ShipPDF and remove the app.

OAuth supports the five named MCP scopes in the permissions table. It does not support the API token wildcard * or webhooks:manage. When a client omits scopes, ShipPDF requests all five MCP scopes; review the consent screen before approving.

Connect your client

ChatGPT

  1. Enable Developer mode in Settings → Security and login, if available to your account.
  2. Open Plugins and create a developer-mode app named ShipPDF.
  3. Enter https://mcp.shippdf.com and select OAuth. Use automatic client discovery rather than supplying static credentials.
  4. Complete ShipPDF sign-in, then select the app in your conversation’s Developer mode menu.

Availability depends on your account and workspace settings. See OpenAI’s developer mode guide for current setup details.

Claude Desktop

  1. Open Customize → Connectors, choose + Add → Add custom connector, and name it ShipPDF.
  2. Enter https://mcp.shippdf.com and continue.
  3. Review the detected authentication settings, choose Sign in now, and complete ShipPDF authorization.
  4. Enable the connector for your conversation.

Workspace policies may control who can add connectors. See Claude’s remote connector guide.

Codex

For OAuth, add the remote server and sign in:

codex mcp add shippdf --url https://mcp.shippdf.com
codex mcp login shippdf

For an API token, add this to ~/.codex/config.toml instead:

[mcp_servers.shippdf]
url = "https://mcp.shippdf.com"
bearer_token_env_var = "SHIPPDF_API_TOKEN"

Set SHIPPDF_API_TOKEN in the environment that launches Codex. Use /mcp in the CLI to inspect the connection. See OpenAI’s MCP configuration guide.

Clients that only support stdio

Use mcp-remote to bridge a local stdio connection to ShipPDF. With Node.js installed, add this to your client’s MCP configuration:

{
  "mcpServers": {
    "shippdf": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://mcp.shippdf.com",
        "--header",
        "Authorization:${SHIPPDF_AUTH_HEADER}"
      ],
      "env": {
        "SHIPPDF_AUTH_HEADER": "Bearer spdf_xxx"
      }
    }
  }
}

Replace the placeholder token and restart your client if it requires a restart to load configuration changes.

Verify the connection

With templates:read granted, ask:

Use ShipPDF to list the published templates I can access.

An empty list can mean there are no published templates within your connection’s resource access. If the tool is missing, check the granted scopes and refresh your client’s tool list. For authentication failures, see Limits and errors.

Next: Capabilities and permissions.