Yes, some clients can connect to remote MCP servers that use API keys—but compatibility depends on how the server expects the key to be sent. Claude Code, VS Code, and Windsurf Cascade document custom HTTP headers. Claude Desktop has a documented service-specific URL-key setup and may need a bridge for custom headers. ChatGPT Developer mode documents OAuth, no authentication, and mixed authentication, but not generic static API-key headers. Cursor’s Atlassian integration is not proof of generic custom-header support.
The comparison below reflects official documentation accessed on October 2, 2026; it is documented support, not a controlled test of one server across all six clients.
What must match for an API-key MCP connection to work?
Check two separate things: the client must support the server’s remote transport, and the client must be able to provide credentials in the exact form the server expects. A server may require a named HTTP header, a key in the URL, OAuth, or a bridge that converts one client connection method into another. Supporting remote MCP alone does not guarantee that a client can authenticate to a particular server.
Before configuring a client, get the server’s endpoint, supported transport, exact header name and token format (if applicable), and any required URL parameter or OAuth flow from its documentation. “Works” means that specific combination is supported—not that every API-key-protected server works in every MCP client.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Which of the six clients document API-key options?
| Client | Documented path | Scope and caveat |
|---|---|---|
| Claude Code | Remote HTTP MCP with custom API-key or bearer headers; configuration can use environment-variable expansion. | Use the header name and token format the server requires. OAuth is also supported for servers that implement it. Claude Code MCP documentation. |
| VS Code | Remote HTTP configuration with optional headers or OAuth. Sensitive input variables can prompt for a value and securely store it for later use. | VS Code tries HTTP Stream first and falls back to SSE if HTTP is unsupported; transport behavior is distinct from the server’s key requirements. VS Code MCP configuration reference. |
| Windsurf Cascade | Remote HTTP configuration with a headers object. Values can be interpolated from an environment variable or file. | The documented example uses a custom API_KEY header. Confirm the required header name and value format with your server. Windsurf MCP documentation. |
| Claude Desktop | ABsmartly documents putting a key in its remote endpoint URL. Its guide recommends mcp-remote to pass a key as a header. |
This is a service-specific setup, not a guarantee for every Claude Desktop connector or server. The cited guide says Claude Desktop does not natively support custom headers for remote servers. ABsmartly’s Claude Desktop instructions. |
| ChatGPT Developer mode | Remote MCP over SSE and streaming HTTP; the reviewed guide names OAuth, no authentication, and mixed authentication. | The guide does not document a generic static API-key-header method. Direct connection to a raw API-key-only server is therefore not established by that documentation. ChatGPT Developer mode documentation. |
| Cursor | Atlassian documents a Cursor integration for its MCP server and says that server can optionally use API-token authentication. | A vendor-specific integration does not establish arbitrary custom-header configuration for every Cursor server. Verify the precise integration and authentication path. Atlassian remote MCP server documentation. |
How to configure a key in clients that document custom headers
VS Code
Workspace MCP configuration lives in .vscode/mcp.json under a top-level servers object. A remote HTTP entry can include a URL, optional headers, and optional OAuth configuration. Use the server’s required header name; don’t assume it is Authorization or API_KEY.
For sensitive values, use a VS Code input variable with a password-style prompt rather than committing a literal secret in the workspace file. VS Code securely stores the value after the first entry. When OAuth is configured, VS Code handles the OAuth flow automatically.
Rank #2
Claude Code
Claude Code’s documented command uses claude mcp add --transport http for a remote HTTP server and accepts a --header argument. Its JSON configuration also supports headers and environment-variable expansion. Match the server’s required header and token format rather than copying an example value blindly.
Windsurf Cascade
Cascade accepts a remote serverUrl or url and a headers object. Its configuration supports ${env:VAR_NAME} and ${file:/path} interpolation. These options let you keep the key outside a literal configuration value; follow your organization’s rules for storing secrets and file permissions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
When is a URL key or bridge needed for Claude Desktop?
The ABsmartly Claude Desktop guide shows that service’s key in a query parameter on the endpoint URL. The same vendor says to use mcp-remote when the key must be sent as a custom header, because Claude Desktop does not natively support custom headers for remote servers. Treat both details as ABsmartly-specific guidance, not as universal behavior for all Claude Desktop connections.
A URL query parameter is not interchangeable with a header: use it only if the server’s own documentation explicitly requires or supports that placement. Avoid exposing real secrets in published examples, shared configuration, or logs; a URL may be copied or recorded in places a prompted or environment-based secret would not be.
Rank #4
- API Security in Action
- Manning Publications
- ABIS BOOK
What do ChatGPT Developer mode and Cursor establish?
ChatGPT Developer mode
The reviewed OpenAI guide supports remote MCP over SSE and streaming HTTP and describes OAuth, no authentication, and mixed authentication. It does not list a generic static API-key header option. If a server offers only a raw API key in a custom header, the guide does not establish that Developer mode can connect to it directly. Check whether that server offers a documented OAuth or other compatible route.
Cursor
Atlassian’s documentation names a Cursor setup for its own remote MCP server and notes that API-token authentication can be enabled or disabled by an organization administrator; scoped credentials are required. That establishes an Atlassian-specific path, not generic support for any server’s arbitrary headers. Confirm the server’s integration instructions and any administrator policy before relying on token authentication.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Quick Recap
Best Value
How to choose a connection path
- Identify the server transport. Confirm whether the endpoint uses remote HTTP/HTTP Stream, SSE, or another documented route, and check that the client supports it.
- Identify credential placement. Find out whether the server expects a custom header, a URL parameter, OAuth, or a vendor-specific bridge.
- Match the exact credential format. For a header, verify its name and whether the value is a raw key or a scheme-prefixed value such as a bearer token.
- Choose a safe secret method. Use a client-supported secure prompt, environment variable, or file interpolation where available. Do not put a real key in a public example or committed configuration.
- Check the evidence scope. Distinguish a generic client configuration feature from an integration documented for one named service. If the client or server documentation does not establish the needed combination, treat compatibility as unconfirmed.
What to do if the connection fails
- Transport error: Recheck the endpoint and the transport the server offers. In VS Code, HTTP Stream is tried first and SSE is the fallback when HTTP is unsupported; this does not resolve a credential mismatch.
- Authentication or authorization error: Verify the header name, key value format, scope, and whether the key is enabled for that server. For Atlassian, an organization administrator can disable API-token authentication, and scoped credentials are required.
- Client has no documented header option: Look for a server-supported OAuth flow, a documented URL-key method, or a vendor-supported bridge. Do not assume an undocumented workaround is safe or supported.
- Secret prompt or interpolation fails: Confirm the variable or file exists in the environment used to launch the client, and check that the configuration syntax matches that client’s documentation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

