Authentication

API key

Gate HTTP access with a shared secret for development only.

Use apiKey() for internal or development gates only. It validates a header and does not set ctx.user. This is not MCP OAuth and not the HTTP API reference at /openapi.json.

Set an API key

export API_KEY=dev-secret-change-me

Configure bitmcp

bitmcp.config.ts
import { defineConfig } from "bitmcp";
import { apiKey } from "bitmcp/auth/api-key";

export default defineConfig({
  auth: apiKey({ env: "API_KEY" }),
});

Clients send the key in the x-api-key header by default.

Verify

  1. Start the server with pnpm dev or pnpm start
  2. Call /mcp without the header and confirm 401
  3. Call with x-api-key: dev-secret-change-me and confirm the request succeeds

Do not use apiKey() for production user identity. Use an OAuth provider from Supabase, Auth0, Better Auth, or Custom.

Options

apiKey(options?: {
  env?: string;
  headerName?: string;
  validate?: (key: string) => boolean | Promise<boolean>;
})
OptionDefaultDescription
env"API_KEY"Environment variable name
headerName"x-api-key"Request header to read
validatecompares to env valueCustom validation function