API keys, the gateway and connecting
Each published server is served at /s/<serverId>/mcp. Clients authenticate with one of that server’s API keys.
On this page

Create a key
Admins create keys on the API keys tab. A key is kvn_ plus 32 random bytes; it is shown
once, with ready-made commands to add the server to Claude Code, and Studio keeps only its
SHA-256. The list shows each key’s prefix and last use.

The command with the key in it is the quickest, but leaves the key in your shell’s history. The bash / zsh and PowerShell tabs read the key without echoing it and pass it through a variable:

Each published server is served at /s/{serverId}/mcp (Streamable HTTP, both protocol eras).
Clients send one of the server’s API keys:
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp \
--header "Authorization: Bearer kvn_..."To keep the key out of your shell history, read it hidden and pass it through a variable:
# bash / zsh
printf 'API key: '; read -rs KERVAN_API_KEY; echo
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp \
--header "Authorization: Bearer $KERVAN_API_KEY"
unset KERVAN_API_KEY# PowerShell
$key = Read-Host "API key" -AsSecureString
$env:KERVAN_API_KEY = [Net.NetworkCredential]::new("", $key).Password
claude mcp add --transport http weather https://studio.example.com/s/<serverId>/mcp --header "Authorization: Bearer $env:KERVAN_API_KEY"
Remove-Item Env:KERVAN_API_KEY; Remove-Variable key- A key works for its own server only.
- Missing, unknown, revoked and other-server keys all get the same
401. - Publishing a version, or publishing an older one again, updates the server in place.
Clients on MCP 2026-07-28 that listen (
subscriptions/listen) getlist_changedat once; 2025-era clients, served statelessly over HTTP, see the new tools on their nexttools/list. - To take a server offline without deleting it, disable it (see Web UI); a disabled server answers 404 like an unknown one.
- A missing, wrong, revoked or other server’s key always gets the same 401 body, which says what
to send:
Unauthorized. Send a valid API key for this server as 'Authorization: Bearer <key>'.
Revoke a key
Revoke asks for confirmation and takes effect on the next request; the key’s open streams are closed at once. Deactivating the user who created a key can revoke their keys in the same step.
For another client, or for the protocol details, see the guide to connecting a server to Claude Code and the MCP protocol notes.