MCPifex API Keys: Authentication for the MCP Gateway
An MCPifex API key is the password your MCP client uses to reach the gateway at https://mcpifex.com/mcp. It starts with mcpx_, belongs to one instance, and can only call the tools you enabled on that instance. You send it in an Authorization: Bearer header, or as the first segment of the URL if your client can't set headers.
Send the key: header or URL
Both forms authenticate the same key and give the same access. Use the header wherever your client supports one.
| Form | Where the key goes | Typical client |
|---|---|---|
| Bearer header | Authorization: Bearer mcpx_... | Claude Code, Claude Desktop, Cursor, curl |
| Path segment | https://mcpifex.com/mcp/mcpx_... | ChatGPT connectors, claude.ai custom connectors |
Treat the key, and the full URL in the path form, like a password. Anyone who has it can call every tool enabled on that instance. Keep it out of shared chats and repos.
Try the header form with curl
This script connects with your key and lists the tools it can use. The gateway answers initialize with an Mcp-Session-Id header, and every later request on that session has to send it back.
#!/bin/sh
# MCPifex — raw MCP handshake over curl (initialize + tools/list).
# Replace <YOUR_MCPX_KEY> with your MCPifex API key (starts "mcpx_"), from
# the portal's API key page. Requires curl only.
set -e
GATEWAY_URL="https://mcpifex.com/mcp"
MCPX_KEY="<YOUR_MCPX_KEY>"
# 1. initialize — the gateway replies with an Mcp-Session-Id response header
# that every later request on this session must echo back.
INIT_HEADERS=$(mktemp)
INIT_BODY=$(mktemp)
curl -sS -D "$INIT_HEADERS" -o "$INIT_BODY" \
-X POST "$GATEWAY_URL" \
-H "Authorization: Bearer $MCPX_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-06-18",
"capabilities": {},
"clientInfo": { "name": "mcpifex-curl-example", "version": "1.0.0" }
}
}'
SESSION_ID=$(grep -i '^mcp-session-id:' "$INIT_HEADERS" | tr -d '\r' | cut -d' ' -f2-)
echo "Mcp-Session-Id: $SESSION_ID"
cat "$INIT_BODY"
echo
rm -f "$INIT_HEADERS" "$INIT_BODY"
# 2. tools/list — filtered to the tools enabled for this API key.
curl -sS -X POST "$GATEWAY_URL" \
-H "Authorization: Bearer $MCPX_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "Mcp-Session-Id: $SESSION_ID" \
-d '{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/list",
"params": {}
}'
echo
The second call returns the filtered tools/list for your key. If you get a 401 instead, see the errors below. For the ChatGPT setup, follow connect MCPifex to ChatGPT.
Where a key comes from
You create an instance of a server in the portal, save its credentials, choose the enabled tools, and then generate the key. Test connection makes a real call first, so a bad password shows up before your client ever tries. The quickstart walks through the whole sequence, and the marketplace shows what you can create an instance of.
The key is shown once, when you create it. If you lose it, generate a new one for the instance.
What a key can call
Three rules decide which tools a key can reach:
tools/listonly returns the tools you switched on. A disabled tool never appears to the client.tools/callon a tool that isn't enabled is refused.- A tool that isn't in MCPifex's catalog for that server is always refused, with no switch to enable it.
PostgreSQL's connect_db is the example. MCPifex never catalogs it, so no key can use it to point the server at a different database. Write tools like execute start switched off, and you turn them on per instance.
Revoke a key
Revoke a key in the portal and new calls stop working within about a minute. The gateway briefly caches key lookups, so the cutoff isn't instant. A session that is already open is cut off on its next tool call.
Errors you can get from a key
- 401: the key is missing, invalid or revoked.
instance_disabled: the instance is switched off, for example after a plan downgrade. See pricing for plan limits.connection_revoked: the connected Google account lost access. Reconnect it in the instance.
These mean the request reached the gateway. Retrying won't help until you fix the cause. The troubleshooting guide covers each one.
As of September 2026, keys work this way for every hosted server, such as PostgreSQL.
Ready to connect?
Host any MCP server behind one endpoint and control exactly what your agents can reach.