Developer documentation
MCP with an API key
API-key MCP connections work well for unattended automation and controlled server environments.
Configure the bearer header
Send a RESTRICTED KEY or SECRET KEY in Authorization. The key binds one organization and environment, so organization selection is unnecessary and cannot override it.
Keep the key private
Store the key in the client’s secret facility. Do not place it in a repository, shared MCP configuration, prompt, URL, log, or browser bundle.