Docs

MCPifex API Keys: Authentication for the MCP Gateway

An MCPifex API key is the password your MCP client uses to reach the gateway at https://mcpifex.com/mcp. It starts with mcpx_, belongs to one instance, and can only call the tools you enabled on that instance. You send it in an Authorization: Bearer header, or as the first segment of the URL if your client can't set headers.

Send the key: header or URL

Both forms authenticate the same key and give the same access. Use the header wherever your client supports one.

FormWhere the key goesTypical client
Bearer headerAuthorization: Bearer mcpx_...Claude Code, Claude Desktop, Cursor, curl
Path segmenthttps://mcpifex.com/mcp/mcpx_...ChatGPT connectors, claude.ai custom connectors

Treat the key, and the full URL in the path form, like a password. Anyone who has it can call every tool enabled on that instance. Keep it out of shared chats and repos.

Try the header form with curl

This script connects with your key and lists the tools it can use. The gateway answers initialize with an Mcp-Session-Id header, and every later request on that session has to send it back.

#!/bin/sh
# MCPifex — raw MCP handshake over curl (initialize + tools/list).
# Replace <YOUR_MCPX_KEY> with your MCPifex API key (starts "mcpx_"), from
# the portal's API key page. Requires curl only.
set -e

GATEWAY_URL="https://mcpifex.com/mcp"
MCPX_KEY="<YOUR_MCPX_KEY>"

# 1. initialize — the gateway replies with an Mcp-Session-Id response header
#    that every later request on this session must echo back.
INIT_HEADERS=$(mktemp)
INIT_BODY=$(mktemp)
curl -sS -D "$INIT_HEADERS" -o "$INIT_BODY" \
  -X POST "$GATEWAY_URL" \
  -H "Authorization: Bearer $MCPX_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "initialize",
    "params": {
      "protocolVersion": "2025-06-18",
      "capabilities": {},
      "clientInfo": { "name": "mcpifex-curl-example", "version": "1.0.0" }
    }
  }'

SESSION_ID=$(grep -i '^mcp-session-id:' "$INIT_HEADERS" | tr -d '\r' | cut -d' ' -f2-)
echo "Mcp-Session-Id: $SESSION_ID"
cat "$INIT_BODY"
echo
rm -f "$INIT_HEADERS" "$INIT_BODY"

# 2. tools/list — filtered to the tools enabled for this API key.
curl -sS -X POST "$GATEWAY_URL" \
  -H "Authorization: Bearer $MCPX_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "Mcp-Session-Id: $SESSION_ID" \
  -d '{
    "jsonrpc": "2.0",
    "id": 2,
    "method": "tools/list",
    "params": {}
  }'
echo

The second call returns the filtered tools/list for your key. If you get a 401 instead, see the errors below. For the ChatGPT setup, follow connect MCPifex to ChatGPT.

Where a key comes from

You create an instance of a server in the portal, save its credentials, choose the enabled tools, and then generate the key. Test connection makes a real call first, so a bad password shows up before your client ever tries. The quickstart walks through the whole sequence, and the marketplace shows what you can create an instance of.

The key is shown once, when you create it. If you lose it, generate a new one for the instance.

What a key can call

Three rules decide which tools a key can reach:

  • tools/list only returns the tools you switched on. A disabled tool never appears to the client.
  • tools/call on a tool that isn't enabled is refused.
  • A tool that isn't in MCPifex's catalog for that server is always refused, with no switch to enable it.

PostgreSQL's connect_db is the example. MCPifex never catalogs it, so no key can use it to point the server at a different database. Write tools like execute start switched off, and you turn them on per instance.

Revoke a key

Revoke a key in the portal and new calls stop working within about a minute. The gateway briefly caches key lookups, so the cutoff isn't instant. A session that is already open is cut off on its next tool call.

Errors you can get from a key

  • 401: the key is missing, invalid or revoked.
  • instance_disabled: the instance is switched off, for example after a plan downgrade. See pricing for plan limits.
  • connection_revoked: the connected Google account lost access. Reconnect it in the instance.

These mean the request reached the gateway. Retrying won't help until you fix the cause. The troubleshooting guide covers each one.

As of September 2026, keys work this way for every hosted server, such as PostgreSQL.