MCP Authentication
Use OAuth for every new MCP connection. The legacy api_key query parameter remains temporarily available for migration, but it is deprecated.
| Method | Status | Credential handling |
|---|---|---|
| OAuth | Recommended for new connections, in preview — see How ready is OAuth? | OAuth access token in the Authorization header |
REST API key in ?api_key= | Deprecated, temporary migration path | API key is embedded in the URL |
OAuth (recommended)
Section titled “OAuth (recommended)”Configure the base server URL without a credential:
https://mcp.nuelink.com/mcpThe live server publishes:
| Field | Value |
|---|---|
issuer | https://mcp.nuelink.com |
authorization_endpoint | https://mcp.nuelink.com/authorize |
token_endpoint | https://mcp.nuelink.com/token |
registration_endpoint | https://mcp.nuelink.com/register |
revocation_endpoint | https://mcp.nuelink.com/token |
grant_types_supported | authorization_code, refresh_token |
response_types_supported | code |
response_modes_supported | query |
code_challenge_methods_supported | S256 |
token_endpoint_auth_methods_supported | client_secret_basic, client_secret_post, none |
bearer_methods_supported | header |
Discovery, dynamic client registration, S256 PKCE validation, and the authorization handoff to Nuelink login are operational and verified.
How ready is OAuth?
Section titled “How ready is OAuth?”API key query parameter (deprecated)
Section titled “API key query parameter (deprecated)”Existing clients can temporarily use:
https://mcp.nuelink.com/mcp?api_key=YOUR_API_KEYDo not use this method for a new integration. A credential in a URL can leak through configuration files, screenshots, browser history, proxy logs, monitoring systems, diagnostics, and support tickets.
If migration is not yet possible:
- Use a dedicated API key for that client.
- Restrict access to the configuration file.
- Keep the populated URL out of tickets, chats, screenshots, prompts, and logs.
- Migrate to OAuth when the client supports it.
- Revoke the old API key after every dependent client has migrated.
No removal date is documented here. Announce one separately before disabling existing clients.
Migrating from an API key to OAuth
Section titled “Migrating from an API key to OAuth”- Remove
?api_key=...from the MCP URL. The URL should be exactlyhttps://mcp.nuelink.com/mcp. - Remove any old custom REST-key header configuration.
- Reconnect and choose OAuth.
- Verify identity with
nuelink_get_me. - After all dependent clients have migrated, revoke the old key from Settings → API.
Disconnecting and revoking
Section titled “Disconnecting and revoking”Use the client’s disconnect or credential-removal mechanism where available. Nuelink token creation and revocation are managed under Settings → API. The server advertises a revocation endpoint, but the complete authenticated refresh/revocation lifecycle has not yet been acceptance-certified.
For the deprecated query-key method, revoke or rotate the associated REST API key under Settings → API.
Multi-brand and team accounts
Section titled “Multi-brand and team accounts”The connection inherits the brands and permissions available to the authenticated user. Start with nuelink_get_me, then resolve the intended brand and collection by name. Never assume the first returned resource is the target.
Rate limits
Section titled “Rate limits”MCP tool calls go through the same public API, so the same limits apply: 30 requests per minute on resource endpoints, inside a route limit of 60 per minute. See Rate Limits.
Security notes
Section titled “Security notes”- Use OAuth for new integrations.
- Keep credentials out of MCP URLs.
- Treat every API key like a password.
- Do not commit tokens, keys, or populated compatibility URLs.
- Review every write-tool call.
- Require explicit confirmation for
QUEUE,SCHEDULE, andIMMEDIATE. - Keep Allow AI to perform sensitive actions off in Settings → API unless someone needs
nuelink_delete_post.
Troubleshooting
Section titled “Troubleshooting”Authorization does not complete. Confirm that the client supports remote Streamable HTTP MCP servers, dynamic registration, OAuth, and S256 PKCE. Use the base endpoint without api_key and consult the client’s current official documentation.
A bearer request returns 401. A REST API key is not an OAuth access token. Complete OAuth instead of placing the REST key in the MCP Authorization header.
A deprecated query-key connection returns 401. Confirm that api_key is present and the API key has not been revoked. Migrate to OAuth rather than treating the compatibility URL as permanent.
Tools work, but shutdown returns 500. Session termination is currently defective: an MCP session DELETE can return Cloudflare Worker Error 1101. Treat the session as not cleanly terminated and do not repeatedly retry the delete request. Report repeatable cases to support@nuelink.com with the client name and approximate time.
Still stuck? Email support@nuelink.com and mention MCP in the subject line.