Agent skill

MCP API Key Authentication

by Yourdaylight in Yourdaylight/stock_datasource

Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.

MITAuto-check passedBackend & APIs

Install MCP API Key Authentication

skills CLI
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-api-key-auth .claude/skills/mcp-api-key-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-api-key-auth
GitHub stars
188
Token cost
~1.2k tokens
SKILL.md length
370 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.

  • Works in 5 steps: Create an API Key → Configure MCP Client → Verify Connectivity → …
  • Creating or revoking MCP API keys for the stock data service
  • SKILL.md covers Purpose, When to Use, Architecture and Workflow, plus 3 more sections
  • Calls curl and python3

What it does

The skill describes a split design. API keys are managed on the HTTP server on port 8000 behind a JWT login, the MCP protocol runs on a separate server on port 8001 and expects the key in request headers, and each tool call is logged to a ClickHouse table, `mcp_tool_usage_log`, with the table queried and the record count. The workflow is to log in for a JWT, create a key whose full value is shown only once, configure the client, verify that a tool list comes back instead of a 401, then review usage history and list or manage keys.

Client setup is shown for Claude Code and Claude Desktop through an `mcpServers` entry in the config or a project `.mcp.json`, and for Cursor through a server URL plus a bearer `Authorization` header. DeepSeek Harness is the exception: it launches the server over local stdio, which skips API keys. Troubleshooting covers 401 responses and invalid or expired keys. The skill names endpoints such as `/api/mcp-keys/create` and `/api/mcp-keys/list`, and the excerpt is cut off before the rest of the endpoint table.

When your agent uses it

  • Creating or revoking MCP API keys for the stock data service
  • Connecting Claude Code or Cursor to the service's MCP server
  • Reviewing which MCP tools were called and how many records they returned
  • Debugging a 401 or expired-key error from an MCP client

Example prompts

  • “Create an MCP API key for the stock data service and show me how to add it to Cursor.”
  • “My MCP client gets a 401 from the data service, so find out why.”
  • “Show the paginated MCP usage history for the last few days.”
  • “List all my MCP API keys and tell me which ones have expired.”

Requirements

  • A running stock data service with its HTTP and MCP servers
  • A JWT login for the service
  • ClickHouse for the usage log

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create an API Key
  2. Configure MCP Client
  3. Verify Connectivity
  4. View Usage Statistics
  5. Manage API Keys

What it can do on your machine

Read from SKILL.md and the folder at commit 3d4dbd2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP API Key Authentication loads about 1.2k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 370 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Yourdaylight/stock_datasource at commit 3d4dbd2, republished under its MIT licence (© Yourdaylight). 370 words, ~1,168 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-api-key-auth/SKILL.md (or your agent's skills folder).
name
mcp-api-key-auth
description
This skill should be used when the user needs to set up, manage, or troubleshoot MCP API Key authentication and tool usage tracking for this stock data service. Use it when configuring external MCP clients (Claude Code, Cursor) to connect to the data service.

Purpose

Enable external MCP clients (Claude Code, Cursor, PicoClaw, DeepSeek Harness) to authenticate with the stock data service using independent API keys, and track per-tool usage (table name, record count) for monitoring.

When to Use

  • User wants to create or manage MCP API keys
  • User wants to configure an external MCP client to connect to this service
  • User wants to view MCP tool usage statistics (which tools called, which tables queried, how many records)
  • User needs to troubleshoot MCP authentication errors (401, invalid key, expired key)

Architecture

  • API Key management is on the HTTP server (port 8000), protected by JWT login
  • MCP protocol is on the MCP server (port 8001), protected by API key in request headers
  • Usage tracking records are stored in ClickHouse mcp_tool_usage_log table

Workflow

1) Create an API Key

First login to get a JWT token, then create an API key:

bash
# Login
JWT=$(curl -s -X POST http://<host>:8000/api/auth/login \
  -H "Content-Type: application/json" \
  -d '{"email":"your@email.com","password":"yourpassword"}' \
  | python3 -c "import sys,json; print(json.load(sys.stdin)['access_token'])")

# Create API key
curl -s -X POST http://<host>:8000/api/mcp-keys/create \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"key_name": "my-cursor-key", "expires_days": 90}'

The response contains the full API key (e.g., sk-a1b2c3d4...). Save it immediately — it is only shown once.

2) Configure MCP Client
Claude Code / Claude Desktop

Add to your MCP configuration (claude_desktop_config.json or project .mcp.json):

json
{
  "mcpServers": {
    "stock-data": {
      "url": "http://<host>:8001/messages",
      "transport": "streamable-http",
      "headers": {
        "Authorization": "Bearer sk-your-api-key-here"
      }
    }
  }
}
Cursor

In Cursor settings, add an MCP server with:

  • URL: http://<host>:8001/messages
  • Header: Authorization: Bearer sk-your-api-key-here
DeepSeek Harness

dsh 不使用 8001/messages。本地 stdio 由 dsh spawn,不走 API Key。见 docs/DEEPSEEK_HARNESS.md。

3) Verify Connectivity
bash
# Should return tool list (not 401)
curl -s -X POST http://<host>:8001/messages \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer sk-your-api-key-here" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
4) View Usage Statistics
bash
# Usage history (paginated)
curl -s "http://<host>:8000/api/mcp-usage/history?page=1&page_size=20" \
  -H "Authorization: Bearer $JWT"

# Aggregated stats (last 30 days)
curl -s "http://<host>:8000/api/mcp-usage/stats?days=30" \
  -H "Authorization: Bearer $JWT"
5) Manage API Keys
bash
# List all keys
curl -s http://<host>:8000/api/mcp-keys/list \
  -H "Authorization: Bearer $JWT"

# Revoke a key
curl -s -X POST http://<host>:8000/api/mcp-keys/revoke \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"key_id": "<key-id>"}'
Show full SKILL.md (154 more words)Show less

Key Endpoints

EndpointMethodAuthDescription
/api/mcp-keys/createPOSTJWTCreate new API key
/api/mcp-keys/listGETJWTList user's API keys
/api/mcp-keys/revokePOSTJWTRevoke an API key
/api/mcp-usage/historyGETJWTPaginated usage history
/api/mcp-usage/statsGETJWTAggregated usage stats
/messages (MCP)POSTAPI KeyMCP protocol endpoint

Troubleshooting

  • 401 "API key required": Missing Authorization header on MCP calls
  • 401 "Invalid or expired API key": Key was revoked or expired — create a new one
  • initialize works but tools/list fails: initialize does not require auth; tools/list and tools/call do
  • Usage not showing up: Usage logging is fire-and-forget; check ClickHouse mcp_tool_usage_log table directly

Verification Checklist

  • API key created and full key returned (shown only once)
  • tools/list returns 401 without API key
  • tools/list returns tool list with valid API key
  • tools/call records usage in mcp_tool_usage_log table
  • Revoked key returns 401 on subsequent calls
  • Usage history API returns correct data
  • Usage stats show daily call counts and top tools

© Yourdaylight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mcp-api-key-auth of Yourdaylight/stock_datasource.

Open the folder on GitHubat commit 3d4dbd2

Compare with similar skills

MCP API Key Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP API Key Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP API Key Authentication this skillYourdaylight/stock_datasource188—~1.2kAutomated safety check: PassMIT
Cdesktopcdesktop-ai/cdesktop157—~697Automated safety check: PassApache-2.0
Atlassian MCP ExpertJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Notion MCPLeoYeAI/openclaw-master-skills2.2k—~4.7kAutomated safety check: PassMIT
Contam MCPhashgraph-online/awesome-codex-plugins1.2k—~3.8kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k62 repos~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Cdesktop

    cdesktop-ai/cdesktop

    Operate the cdesktop coding-session environment — agent teams, session management, file conventions.

    157 GitHub stars~697 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Atlassian MCP Expert

    Jeffallan/claude-skills

    Queries and edits Jira issues and Confluence pages through an MCP server, covering JQL and CQL queries, server setup, authentication and sprint or backlog workflows.

    12k GitHub stars~1.3k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Notion MCP

    LeoYeAI/openclaw-master-skills

    Notion MCP integration with managed authentication. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Contam MCP

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when working with CONTAM projects through the local contam MCP server, including discovering CONTAM executables and API integrations, listing .prj/.sim/.wth/.ctm files…

    1.2k GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 62 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed

More from Yourdaylight/stock_datasource

  • Real-Time Stock Quote Subscriber

    Yourdaylight/stock_datasource

    Streams live A-share, Hong Kong and ETF quotes from a receiver node over a local WebSocket server, with built-in price and volume alert rules.

    188 GitHub stars~559 tokensUpdated 29 days ago
    Auto-check passed
  • Tushare Plugin Builder

    Yourdaylight/stock_datasource

    Turns a Tushare API doc URL into a full data plugin for the stock_datasource repo: extractor, ClickHouse schema, query service, config and curl examples.

    188 GitHub stars~2.5k tokensUpdated 29 days ago
    Auto-check passed
  • Stock Market Data MCP Query

    Yourdaylight/stock_datasource

    Queries historical A-share, Hong Kong stock, ETF and index data through an MCP server: daily K-lines, financial statements, market indicators and screening.

    188 GitHub stars~1.1k tokensUpdated 29 days ago
    Auto-check passed
  • Stock Data Assistant

    Yourdaylight/stock_datasource

    Queries A-share, Hong Kong, ETF and index market data over MCP, streams live quotes by WebSocket, and lets you drive both from WeChat through picoclaw.

    188 GitHub stars~1.2k tokensUpdated 29 days ago
    Auto-check: notes

Questions about MCP API Key Authentication

What does MCP API Key Authentication do?

Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics. The skill describes a split design. API keys are managed on the HTTP server on port 8000 behind a JWT login, the MCP protocol runs on a separate server on port 8001 and expects the key in request headers, and each tool call is logged to a ClickHouse table, `mcp_tool_usage_log`, with the table queried and the record count.

When should I use MCP API Key Authentication?

MCP API Key Authentication fits situations like: creating or revoking MCP API keys for the stock data service; connecting Claude Code or Cursor to the service's MCP server; reviewing which MCP tools were called and how many records they returned; debugging a 401 or expired-key error from an MCP client.

How do I install MCP API Key Authentication in Claude Code?

Run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a claude-code`. Or copy the skill folder (skills/mcp-api-key-auth in Yourdaylight/stock_datasource) into .claude/skills/mcp-api-key-auth in your project. Claude Code loads it when a task matches its description.

How do I install MCP API Key Authentication in Codex?

Run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a codex`. Or copy the skill folder (skills/mcp-api-key-auth in Yourdaylight/stock_datasource) into .agents/skills/mcp-api-key-auth in your project. Codex loads it when a task matches its description.

Can I use MCP API Key Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-api-key-auth, .gemini/skills/mcp-api-key-auth, .github/skills/mcp-api-key-auth and .opencode/skills/mcp-api-key-auth in your project.

What does MCP API Key Authentication need to run?

Going by SKILL.md and its folder, MCP API Key Authentication needs the command-line tools its instructions call (curl and python3). Our summary lists: A running stock data service with its HTTP and MCP servers; A JWT login for the service; ClickHouse for the usage log.

Does MCP API Key Authentication access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is MCP API Key Authentication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP API Key Authentication use?

MCP API Key Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP API Key Authentication use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP API Key Authentication?

Skills that share tags, products or a category with MCP API Key Authentication: Cdesktop (cdesktop-ai/cdesktop, 157 stars), Atlassian MCP Expert (Jeffallan/claude-skills, 12k stars), Notion MCP (LeoYeAI/openclaw-master-skills, 2.2k stars) and Contam MCP (hashgraph-online/awesome-codex-plugins, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP API Key Authentication?

Yourdaylight (a GitHub user) maintains it in Yourdaylight/stock_datasource, which has 188 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 8, 2026.

Source: Yourdaylight/stock_datasource on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.