API keys, the gateway and connecting

Each published server is served at /s/<serverId>/mcp. Clients authenticate with one of that server’s API keys.

On this page
The API keys tab: three keys with their names, prefixes, creation and last-use times, and a Revoke button each.

Create a key

Admins create keys on the API keys tab. A key is kvn_ plus 32 random bytes; it is shown once, with ready-made commands to add the server to Claude Code, and Studio keeps only its SHA-256. The list shows each key’s prefix and last use.

The new-key dialog: the key in a read-only field and the claude mcp add command with the key in it.
The key itself appears in this dialog only (shown here with a placeholder).

The command with the key in it is the quickest, but leaves the key in your shell’s history. The bash / zsh and PowerShell tabs read the key without echoing it and pass it through a variable:

The bash / zsh tab: a command that reads the key hidden into a variable, adds the server and unsets the variable.

Each published server is served at /s/{serverId}/mcp (Streamable HTTP, both protocol eras). Clients send one of the server’s API keys:

sh
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp \
  --header "Authorization: Bearer kvn_..."

To keep the key out of your shell history, read it hidden and pass it through a variable:

sh
# bash / zsh
printf 'API key: '; read -rs KERVAN_API_KEY; echo
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp \
  --header "Authorization: Bearer $KERVAN_API_KEY"
unset KERVAN_API_KEY
powershell
# PowerShell
$key = Read-Host "API key" -AsSecureString
$env:KERVAN_API_KEY = [Net.NetworkCredential]::new("", $key).Password
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp --header "Authorization: Bearer $env:KERVAN_API_KEY"
Remove-Item Env:KERVAN_API_KEY; Remove-Variable key
  • A key works for its own server only.
  • Missing, unknown, revoked and other-server keys all get the same 401.
  • Publishing a version, or publishing an older one again, updates the server in place. Clients on MCP 2026-07-28 that listen (subscriptions/listen) get list_changed at once; 2025-era clients, served statelessly over HTTP, see the new tools on their next tools/list.
  • To take a server offline without deleting it, disable it (see Web UI); a disabled server answers 404 like an unknown one.
  • A missing, wrong, revoked or other server’s key always gets the same 401 body, which says what to send: Unauthorized. Send a valid API key for this server as 'Authorization: Bearer <key>'.

Revoke a key

Revoke asks for confirmation and takes effect on the next request; the key’s open streams are closed at once. Deactivating the user who created a key can revoke their keys in the same step.

For another client, or for the protocol details, see the guide to connecting a server to Claude Code and the MCP protocol notes.