# Context7 MCP Authentication Methods: API Key vs OAuth 2.0 Guide

> Context7 MCP offers API key and OAuth 2.0 authentication. Understand the differences and choose the right method for your needs.

- Repository: [Upstash/context7](https://github.com/upstash/context7)
- Tags: api-reference
- Published: 2026-02-16

---

**Context7 MCP supports both API key and OAuth 2.0 authentication, with API keys working across all transport types while OAuth is restricted to remote HTTP connections only.**

Context7 MCP (Model Context Protocol) provides flexible authentication options to secure your AI-assisted development workflows. Understanding these Context7 MCP authentication methods ensures you choose the right approach for your specific deployment scenario, whether you're running local stdio connections or remote HTTP-based integrations.

## Understanding Context7 MCP Authentication Options

The Context7 MCP server implements two distinct authentication mechanisms to accommodate different deployment architectures. According to the source code in [`packages/mcp/src/lib/api.ts`](https://github.com/upstash/context7/blob/main/packages/mcp/src/lib/api.ts), the server can authenticate requests using either a static API key passed via headers or environment variables, or through a dynamic OAuth 2.0 flow for web-based integrations.

## API Key Authentication

### How API Key Authentication Works

API key authentication is the most versatile method supported by Context7 MCP. The server reads the `CONTEXT7_API_KEY` header from incoming requests, or alternatively checks the `--api-key` CLI flag and `CONTEXT7_API_KEY` environment variable. This implementation, documented in [`packages/mcp/README.md`](https://github.com/upstash/context7/blob/main/packages/mcp/README.md) (lines 1370-1372), ensures compatibility across all supported transport protocols.

### Configuration Examples

For HTTP-based connections, configure your MCP client with the API key in the headers:

```json
{
  "mcpServers": {
    "context7": {
      "url": "https://mcp.context7.com/mcp",
      "headers": {
        "CONTEXT7_API_KEY": "YOUR_API_KEY"
      }
    }
  }
}

```

For local stdio transport connections, set the environment variable before launching the server:

```bash
export CONTEXT7_API_KEY="YOUR_API_KEY"

```

### When to Use API Key Authentication

Use API key authentication when:
- Running local MCP servers via stdio transport
- Deploying in environments where OAuth flows are impractical
- Requiring simple, stateless authentication for CI/CD pipelines
- Connecting from clients that don't support OAuth 2.0 flows

## OAuth 2.0 Authentication

### How OAuth 2.0 Works in Context7 MCP

Context7 MCP implements the MCP OAuth specification for secure, token-based authentication. The OAuth endpoint at `https://mcp.context7.com/mcp/oauth` handles the authorization flow, returning an access token that subsequent requests use for authentication. This mechanism is detailed in the main [`README.md`](https://github.com/upstash/context7/blob/main/README.md) (lines 158-169) under the "OAuth Authentication" section.

### Configuring OAuth for Remote HTTP Connections

To switch from API key to OAuth authentication, modify the URL endpoint in your MCP client configuration:

```diff
- "url": "https://mcp.context7.com/mcp"
+ "url": "https://mcp.context7.com/mcp/oauth"

```

After changing the endpoint, the MCP client automatically initiates the OAuth flow. No `CONTEXT7_API_KEY` header is required when using OAuth, as the access token handles authentication.

### Limitations of OAuth with stdio Transport

OAuth 2.0 authentication is **only available for remote HTTP connections**. As documented in [`packages/mcp/README.md`](https://github.com/upstash/context7/blob/main/packages/mcp/README.md) (lines 33-44), the OAuth flow requires web-based redirection and token exchange that cannot be performed over local stdio transports. For local MCP server connections, you must use API key authentication.

## Key Differences and Use Cases

| Authentication Method | Transport Support | Best For | Configuration |
|----------------------|-------------------|----------|---------------|
| **API Key** | HTTP and stdio | Local development, CI/CD, simple deployments | `CONTEXT7_API_KEY` header, env var, or CLI flag |
| **OAuth 2.0** | HTTP only | Production web apps, secure multi-user environments | `https://mcp.context7.com/mcp/oauth` endpoint |

## Implementation Details from Source Code

The authentication logic resides in several key files within the `upstash/context7` repository:

- **[`packages/mcp/src/lib/api.ts`](https://github.com/upstash/context7/blob/main/packages/mcp/src/lib/api.ts)**: Implements the core request handling, reading the `CONTEXT7_API_KEY` header and routing to the OAuth endpoint when configured.
- **[`packages/mcp/README.md`](https://github.com/upstash/context7/blob/main/packages/mcp/README.md)** (lines 33-44, 1370-1372): Documents both authentication methods and their transport limitations.
- **[`plugins/cursor/context7/mcp.json`](https://github.com/upstash/context7/blob/main/plugins/cursor/context7/mcp.json)** (lines 2-4): Contains the OAuth endpoint URL (`https://mcp.context7.com/mcp/oauth`) used by the Cursor IDE plugin.
- **[`README.md`](https://github.com/upstash/context7/blob/main/README.md)** (lines 158-169): Provides high-level overview of OAuth authentication and links to the MCP OAuth specification.

## Summary

- Context7 MCP supports **API key** and **OAuth 2.0** authentication methods.
- **API key authentication** works with both HTTP and stdio transports, configured via headers, environment variables, or CLI flags.
- **OAuth 2.0** is restricted to remote HTTP connections only and cannot be used with local stdio transports.
- The OAuth endpoint is located at `https://mcp.context7.com/mcp/oauth`, while API key authentication uses the standard `https://mcp.context7.com/mcp` endpoint.
- Configuration details are documented in [`packages/mcp/README.md`](https://github.com/upstash/context7/blob/main/packages/mcp/README.md) and implemented in [`packages/mcp/src/lib/api.ts`](https://github.com/upstash/context7/blob/main/packages/mcp/src/lib/api.ts).

## Frequently Asked Questions

### Can I use OAuth with local stdio connections?

No, OAuth 2.0 authentication is only available for remote HTTP connections. According to the source code in [`packages/mcp/README.md`](https://github.com/upstash/context7/blob/main/packages/mcp/README.md) (lines 33-44), the OAuth flow requires web-based redirection that cannot be performed over stdio transports. For local MCP servers, you must use API key authentication via the `CONTEXT7_API_KEY` environment variable or header.

### How do I switch from API key to OAuth authentication?

To switch authentication methods, change the URL endpoint in your MCP client configuration from `https://mcp.context7.com/mcp` to `https://mcp.context7.com/mcp/oauth`. As shown in the [`plugins/cursor/context7/mcp.json`](https://github.com/upstash/context7/blob/main/plugins/cursor/context7/mcp.json) file (lines 2-4), the OAuth endpoint handles the MCP OAuth specification flow automatically. Remove the `CONTEXT7_API_KEY` header from your configuration, as the access token obtained through OAuth will handle authentication instead.

### Where is the OAuth endpoint configured in the Cursor plugin?

The OAuth endpoint is configured in [`plugins/cursor/context7/mcp.json`](https://github.com/upstash/context7/blob/main/plugins/cursor/context7/mcp.json) at lines 2-4. This JSON configuration file specifies `"url": "https://mcp.context7.com/mcp/oauth"`, which directs the Cursor IDE to use OAuth authentication rather than API key authentication when connecting to the Context7 MCP server.

### Is API key authentication secure for production use?

API key authentication is secure for production use when transmitted over HTTPS, as implemented in [`packages/mcp/src/lib/api.ts`](https://github.com/upstash/context7/blob/main/packages/mcp/src/lib/api.ts). However, for multi-user environments or applications requiring granular permission scopes, OAuth 2.0 is the recommended approach. OAuth provides better security for distributed systems by avoiding the storage of long-lived API keys in client configurations and supporting token expiration and refresh mechanisms as defined in the MCP OAuth specification.