The CLI can read the key from an environment variable, so it stays out of the file. Run both lines in the same window. This route is for the CLI: the Codex app does not see variables you set in a terminal.
export SUPERSCRIBE_API_KEY=ss_YOUR_KEY
codex mcp add superscribe --url https://superscribe.io/mcp --bearer-token-env-var SUPERSCRIBE_API_KEY
Check it with codex mcp list, or type /mcp inside the CLI. To keep the variable, add the export line to your shell profile, for example ~/.zshrc. Older CLI versions have no --url flag, but they read the same file.