# Authenticate a client

Create a Beacon client with an agent key or an OAuth access token.

Use an agent key for direct automation. Use an OAuth access token when your application completed Beacon OAuth.

An access token is a secret value that gives a client limited access to Beacon.

## Use an agent key

```ts
import { BeaconClient } from "@beacon/sdk";

const agentKey = process.env.BEACON_AGENT_KEY;
if (!agentKey) throw new Error("BEACON_AGENT_KEY is required");

const beacon = new BeaconClient({
  agentKey,
  baseUrl: "https://postwithbeacon.com",
});
```

## Use an access token

```ts
const beacon = new BeaconClient({
  accessToken,
  baseUrl: "https://postwithbeacon.com",
});
```

Provide exactly one credential. The client rejects empty credentials and URLs that contain embedded credentials.

## Check the selected workspace

```ts
const identity = await beacon.identity.get();

console.log(identity.workspaceId);
console.log(identity.credential.permissions);
```

Beacon selects the workspace from the credential. Do not accept a workspace ID from a browser as authorization.
