# API quickstart (/docs/api-quickstart)



## Find your Workspaces [#find-your-workspaces]

Send the current signed-in user's Supabase access token as a Bearer token.
Current access returns every active Workspace available to that user, so it
does not need `SMB-Workspace-Id`.

```bash
curl https://api.smb.co/v1/me \
  --header "Authorization: Bearer $SUPABASE_ACCESS_TOKEN"
```

A successful response includes `workspace_ids` and details for each active
Workspace membership. Choose one of those IDs for later Workspace operations;
the ID selects context but never grants access.

## Service-account automation [#service-account-automation]

For unattended jobs, create a Workspace API key. The key is already pinned to
one Workspace, so current access does not need a separate Workspace header. SMB
stores only a one-way hash, so the full secret cannot be displayed again.

```bash
curl https://api.smb.co/v1/me \
  --header "Authorization: Bearer $SMB_API_KEY"
```

## Connect an agent [#connect-an-agent]

Use [MCP setup](/docs/agent-setup) for ChatGPT, Claude, Codex, Cursor, Copilot,
Gemini, or another compatible client. Customer MCP connections use OAuth so a
person can review and revoke the connection without copying an API key into the
client.

<Callout title="Keep credentials private">
  Never put user access tokens or API keys in screenshots, source control, or
  chat messages. Store service-account API keys as secrets.
</Callout>
