MCP Authentication: OAuth 2.1 vs. API Keys Explained
MCP authentication is how an MCP server checks who is calling it. The spec defines an optional OAuth flow for servers reached over HTTP. Local servers skip that and read credentials from environment variables. MCPifex uses a simple API key for each instance.
A simple way to picture it
Say you connect Claude to a database through MCP. Two separate logins are in play. Claude has to prove itself to the server, and the server has to prove itself to the database. The first is MCP authentication. The second is whatever the database needs, like a password.
Local and remote servers differ
The split follows where the server runs:
- Local (stdio). Your AI app starts the server as a subprocess on your machine. A credential in an environment variable is enough, because nothing crosses a network.
- Remote (HTTP). Anyone who can reach the URL can try to call it. The MCP authorization spec covers this with an OAuth 2.1 flow, but it's optional. Many remote servers just check a bearer key their operator issued.
Getting this wrong is how secrets end up in the wrong place, like a static key inside a browser app.
How it works on MCPifex
As of September 2026, there are two credentials, kept apart. The first is your mcpx_... API key, which authenticates your MCP client to the gateway. You send it as an Authorization: Bearer header, or as the first part of the URL path for clients that can't send headers.
The second is whatever the server behind it needs. That might be a database password, or an OAuth connection to a Google account for Search Console. You save it once in the portal, and the gateway attaches it on every call. You never type it into your AI client.
Keys you can revoke
If a key leaks, revoke it in the portal. New calls stop within about a minute, and any open session is cut off on its next tool call. Full details are in API keys and authentication, and the marketplace shows what each server needs.
Related terms
See MCP gateway, the component that usually sits at this boundary, and MCP server. For safer setups overall, read the MCP security guide.
Sources
Ready to try it?
Host any MCP server behind one endpoint and control exactly what your agents can reach.