Skip to content

MCP Authentication

Use OAuth for every new MCP connection. The legacy api_key query parameter remains temporarily available for migration, but it is deprecated.

MethodStatusCredential handling
OAuthRecommended for new connections, in preview — see How ready is OAuth?OAuth access token in the Authorization header
REST API key in ?api_key=Deprecated, temporary migration pathAPI key is embedded in the URL

Configure the base server URL without a credential:

https://mcp.nuelink.com/mcp

The live server publishes:

FieldValue
issuerhttps://mcp.nuelink.com
authorization_endpointhttps://mcp.nuelink.com/authorize
token_endpointhttps://mcp.nuelink.com/token
registration_endpointhttps://mcp.nuelink.com/register
revocation_endpointhttps://mcp.nuelink.com/token
grant_types_supportedauthorization_code, refresh_token
response_types_supportedcode
response_modes_supportedquery
code_challenge_methods_supportedS256
token_endpoint_auth_methods_supportedclient_secret_basic, client_secret_post, none
bearer_methods_supportedheader

Discovery, dynamic client registration, S256 PKCE validation, and the authorization handoff to Nuelink login are operational and verified.

Existing clients can temporarily use:

https://mcp.nuelink.com/mcp?api_key=YOUR_API_KEY

Do not use this method for a new integration. A credential in a URL can leak through configuration files, screenshots, browser history, proxy logs, monitoring systems, diagnostics, and support tickets.

If migration is not yet possible:

  1. Use a dedicated API key for that client.
  2. Restrict access to the configuration file.
  3. Keep the populated URL out of tickets, chats, screenshots, prompts, and logs.
  4. Migrate to OAuth when the client supports it.
  5. Revoke the old API key after every dependent client has migrated.

No removal date is documented here. Announce one separately before disabling existing clients.

  1. Remove ?api_key=... from the MCP URL. The URL should be exactly https://mcp.nuelink.com/mcp.
  2. Remove any old custom REST-key header configuration.
  3. Reconnect and choose OAuth.
  4. Verify identity with nuelink_get_me.
  5. After all dependent clients have migrated, revoke the old key from Settings → API.

Use the client’s disconnect or credential-removal mechanism where available. Nuelink token creation and revocation are managed under Settings → API. The server advertises a revocation endpoint, but the complete authenticated refresh/revocation lifecycle has not yet been acceptance-certified.

For the deprecated query-key method, revoke or rotate the associated REST API key under Settings → API.

The connection inherits the brands and permissions available to the authenticated user. Start with nuelink_get_me, then resolve the intended brand and collection by name. Never assume the first returned resource is the target.

MCP tool calls go through the same public API, so the same limits apply: 30 requests per minute on resource endpoints, inside a route limit of 60 per minute. See Rate Limits.

  • Use OAuth for new integrations.
  • Keep credentials out of MCP URLs.
  • Treat every API key like a password.
  • Do not commit tokens, keys, or populated compatibility URLs.
  • Review every write-tool call.
  • Require explicit confirmation for QUEUE, SCHEDULE, and IMMEDIATE.
  • Keep Allow AI to perform sensitive actions off in Settings → API unless someone needs nuelink_delete_post.

Authorization does not complete. Confirm that the client supports remote Streamable HTTP MCP servers, dynamic registration, OAuth, and S256 PKCE. Use the base endpoint without api_key and consult the client’s current official documentation.

A bearer request returns 401. A REST API key is not an OAuth access token. Complete OAuth instead of placing the REST key in the MCP Authorization header.

A deprecated query-key connection returns 401. Confirm that api_key is present and the API key has not been revoked. Migrate to OAuth rather than treating the compatibility URL as permanent.

Tools work, but shutdown returns 500. Session termination is currently defective: an MCP session DELETE can return Cloudflare Worker Error 1101. Treat the session as not cleanly terminated and do not repeatedly retry the delete request. Report repeatable cases to support@nuelink.com with the client name and approximate time.

Still stuck? Email support@nuelink.com and mention MCP in the subject line.