Authentication
API key
Gate HTTP access with a shared secret for development only.
Use apiKey() for internal or development gates only. It validates a header and does not set ctx.user. This is not MCP OAuth and not the HTTP API reference at /openapi.json.
Set an API key
export API_KEY=dev-secret-change-meConfigure bitmcp
import { defineConfig } from "bitmcp";
import { apiKey } from "bitmcp/auth/api-key";
export default defineConfig({
auth: apiKey({ env: "API_KEY" }),
});Clients send the key in the x-api-key header by default.
Verify
- Start the server with
pnpm devorpnpm start - Call
/mcpwithout the header and confirm401 - Call with
x-api-key: dev-secret-change-meand confirm the request succeeds
Do not use apiKey() for production user identity. Use an OAuth provider from Supabase, Auth0, Better Auth, or Custom.
Options
apiKey(options?: {
env?: string;
headerName?: string;
validate?: (key: string) => boolean | Promise<boolean>;
})| Option | Default | Description |
|---|---|---|
env | "API_KEY" | Environment variable name |
headerName | "x-api-key" | Request header to read |
validate | compares to env value | Custom validation function |