Safely connect AI assistants: OAuth or API key?
Two types of authentication
An assistant accessing Same-QR needs proof that it is allowed to do so. ChatGPT and Claude.ai use an OAuth connection, while coding agents like Claude Code, Cursor, and Codex, as well as custom scripts, use an API key.
How OAuth works
You know OAuth from "Sign in with Google". The assistant sends you to the service, you log in there and grant access. The assistant receives authorization, but never your password. With Same-QR, you determine what it is allowed to do via checkboxes: without a checkmark, only read access; with "Also create and change texts", more; with "Also change targets, take offline and delete", everything. This is how it works when you add Same-QR to ChatGPT or Claude.ai as a connector with the address https://sameqr.com/api/mcp.
Why keys do not belong in the chat
An API key is a master key. What is in the chat remains in the history, may end up in exports, and is transmitted to the provider. Therefore: Never copy a key or password into a chat window. For chat assistants, use OAuth; for everything else, use environment variables.
When an API key is appropriate
Programs without browser windows, i.e., scripts, CI pipelines, and coding agents in the terminal, work with keys. With Same-QR, you create them under Account, "Access for CLI, scripts and agents", select "read only", "read + write" (create, change names and text), or "full" (also change targets, take offline, delete), and a duration, and store them as SAMEQR_API_KEY. The configurations for Claude Code, Cursor, and Codex only reference this variable; the key itself is stored in no file.
sameqr mcpThis command displays the completed entries for all three programs.
Revoke access
- Disconnect the connection in the Same-QR dashboard under Account, Connected Apps, and remove the connector in ChatGPT or Claude.ai.
- Revoke the API key in the dashboard; it becomes invalid immediately.
- If you suspect a compromise, change the password: This revokes all keys on Same-QR at once.
Conclusion: why Same-QR
Same-QR offers the appropriate login for each assistant: OAuth for ChatGPT and Claude.ai, keys in three levels for coding agents and scripts, with duration, one-time display, and immediate revocation. Security that does not get in the way.
Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.
Frequently asked questions
No. You log in directly to Same-QR; ChatGPT only receives the permission.
They often run in the terminal or in pipelines without a browser window. In that context, a key in an environment variable is the standard approach.
Revoke it immediately in the dashboard and create a new one.
Reserve your spot before we go live.
One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.
- Your free account is reserved — there is nothing to pay yet anyway
- 90 days of unlimited destination changes instead of 30, only for early sign-ups
- Launch price locked in, even if we raise prices later
By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.