Cdesktop
cdesktop-ai/cdesktop
Operate the cdesktop coding-session environment — agent teams, session management, file conventions.
Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-api-key-auth .claude/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .claude/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/mcp-api-key-auth .agents/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .agents/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/mcp-api-key-auth .cursor/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .cursor/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Yourdaylight/stock_datasource.git --path skills/mcp-api-key-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/mcp-api-key-auth .gemini/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .gemini/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/mcp-api-key-auth .github/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .github/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Yourdaylight/stock_datasource mcp-api-key-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Yourdaylight/stock_datasource.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/mcp-api-key-auth .opencode/skills/mcp-api-key-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mcp-api-key-auth" agent skill from https://github.com/Yourdaylight/stock_datasource/tree/main/skills/mcp-api-key-auth into .opencode/skills/mcp-api-key-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-api-key-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mcp-api-key-authSets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.
The skill describes a split design. API keys are managed on the HTTP server on port 8000 behind a JWT login, the MCP protocol runs on a separate server on port 8001 and expects the key in request headers, and each tool call is logged to a ClickHouse table, `mcp_tool_usage_log`, with the table queried and the record count. The workflow is to log in for a JWT, create a key whose full value is shown only once, configure the client, verify that a tool list comes back instead of a 401, then review usage history and list or manage keys.
Client setup is shown for Claude Code and Claude Desktop through an `mcpServers` entry in the config or a project `.mcp.json`, and for Cursor through a server URL plus a bearer `Authorization` header. DeepSeek Harness is the exception: it launches the server over local stdio, which skips API keys. Troubleshooting covers 401 responses and invalid or expired keys. The skill names endpoints such as `/api/mcp-keys/create` and `/api/mcp-keys/list`, and the excerpt is cut off before the rest of the endpoint table.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3d4dbd2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
MCP API Key Authentication loads about 1.2k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 370 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Yourdaylight/stock_datasource at commit 3d4dbd2, republished under its MIT licence (© Yourdaylight). 370 words, ~1,168 tokens.
.claude/skills/mcp-api-key-auth/SKILL.md (or your agent's skills folder).Enable external MCP clients (Claude Code, Cursor, PicoClaw, DeepSeek Harness) to authenticate with the stock data service using independent API keys, and track per-tool usage (table name, record count) for monitoring.
mcp_tool_usage_log tableFirst login to get a JWT token, then create an API key:
# Login
JWT=$(curl -s -X POST http://<host>:8000/api/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"your@email.com","password":"yourpassword"}' \
| python3 -c "import sys,json; print(json.load(sys.stdin)['access_token'])")
# Create API key
curl -s -X POST http://<host>:8000/api/mcp-keys/create \
-H "Authorization: Bearer $JWT" \
-H "Content-Type: application/json" \
-d '{"key_name": "my-cursor-key", "expires_days": 90}'The response contains the full API key (e.g., sk-a1b2c3d4...). Save it immediately — it is only shown once.
Add to your MCP configuration (claude_desktop_config.json or project .mcp.json):
{
"mcpServers": {
"stock-data": {
"url": "http://<host>:8001/messages",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer sk-your-api-key-here"
}
}
}
}In Cursor settings, add an MCP server with:
http://<host>:8001/messagesAuthorization: Bearer sk-your-api-key-heredsh 不使用 8001/messages。本地 stdio 由 dsh spawn,不走 API Key。见 docs/DEEPSEEK_HARNESS.md。
# Should return tool list (not 401)
curl -s -X POST http://<host>:8001/messages \
-H "Content-Type: application/json" \
-H "Authorization: Bearer sk-your-api-key-here" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'# Usage history (paginated)
curl -s "http://<host>:8000/api/mcp-usage/history?page=1&page_size=20" \
-H "Authorization: Bearer $JWT"
# Aggregated stats (last 30 days)
curl -s "http://<host>:8000/api/mcp-usage/stats?days=30" \
-H "Authorization: Bearer $JWT"# List all keys
curl -s http://<host>:8000/api/mcp-keys/list \
-H "Authorization: Bearer $JWT"
# Revoke a key
curl -s -X POST http://<host>:8000/api/mcp-keys/revoke \
-H "Authorization: Bearer $JWT" \
-H "Content-Type: application/json" \
-d '{"key_id": "<key-id>"}'| Endpoint | Method | Auth | Description |
|---|---|---|---|
/api/mcp-keys/create | POST | JWT | Create new API key |
/api/mcp-keys/list | GET | JWT | List user's API keys |
/api/mcp-keys/revoke | POST | JWT | Revoke an API key |
/api/mcp-usage/history | GET | JWT | Paginated usage history |
/api/mcp-usage/stats | GET | JWT | Aggregated usage stats |
/messages (MCP) | POST | API Key | MCP protocol endpoint |
Authorization header on MCP callsinitialize works but tools/list fails: initialize does not require auth; tools/list and tools/call domcp_tool_usage_log table directlytools/list returns 401 without API keytools/list returns tool list with valid API keytools/call records usage in mcp_tool_usage_log table© Yourdaylight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/mcp-api-key-auth of Yourdaylight/stock_datasource.
Open the folder on GitHubat commit 3d4dbd2
MCP API Key Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| MCP API Key Authentication this skillYourdaylight/stock_datasource | 188 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Cdesktopcdesktop-ai/cdesktop | 157 | — | ~697 | Automated safety check: Pass | Apache-2.0 | |
| Atlassian MCP ExpertJeffallan/claude-skills | 12k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Notion MCPLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Contam MCPhashgraph-online/awesome-codex-plugins | 1.2k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server Builderanthropics/skills | 180k | 62 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 |
cdesktop-ai/cdesktop
Operate the cdesktop coding-session environment — agent teams, session management, file conventions.
Jeffallan/claude-skills
Queries and edits Jira issues and Confluence pages through an MCP server, covering JQL and CQL queries, server setup, authentication and sprint or backlog workflows.
LeoYeAI/openclaw-master-skills
Notion MCP integration with managed authentication. An agent skill from LeoYeAI/openclaw-master-skills.
hashgraph-online/awesome-codex-plugins
A skill your agent uses when working with CONTAM projects through the local contam MCP server, including discovering CONTAM executables and API integrations, listing .prj/.sim/.wth/.ctm files…
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
Yourdaylight/stock_datasource
Streams live A-share, Hong Kong and ETF quotes from a receiver node over a local WebSocket server, with built-in price and volume alert rules.
Yourdaylight/stock_datasource
Turns a Tushare API doc URL into a full data plugin for the stock_datasource repo: extractor, ClickHouse schema, query service, config and curl examples.
Yourdaylight/stock_datasource
Queries historical A-share, Hong Kong stock, ETF and index data through an MCP server: daily K-lines, financial statements, market indicators and screening.
Yourdaylight/stock_datasource
Queries A-share, Hong Kong, ETF and index market data over MCP, streams live quotes by WebSocket, and lets you drive both from WeChat through picoclaw.
Works with
Categories
Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics. The skill describes a split design. API keys are managed on the HTTP server on port 8000 behind a JWT login, the MCP protocol runs on a separate server on port 8001 and expects the key in request headers, and each tool call is logged to a ClickHouse table, `mcp_tool_usage_log`, with the table queried and the record count.
MCP API Key Authentication fits situations like: creating or revoking MCP API keys for the stock data service; connecting Claude Code or Cursor to the service's MCP server; reviewing which MCP tools were called and how many records they returned; debugging a 401 or expired-key error from an MCP client.
Run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a claude-code`. Or copy the skill folder (skills/mcp-api-key-auth in Yourdaylight/stock_datasource) into .claude/skills/mcp-api-key-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a codex`. Or copy the skill folder (skills/mcp-api-key-auth in Yourdaylight/stock_datasource) into .agents/skills/mcp-api-key-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Yourdaylight/stock_datasource --skill mcp-api-key-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-api-key-auth, .gemini/skills/mcp-api-key-auth, .github/skills/mcp-api-key-auth and .opencode/skills/mcp-api-key-auth in your project.
Going by SKILL.md and its folder, MCP API Key Authentication needs the command-line tools its instructions call (curl and python3). Our summary lists: A running stock data service with its HTTP and MCP servers; A JWT login for the service; ClickHouse for the usage log.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
MCP API Key Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with MCP API Key Authentication: Cdesktop (cdesktop-ai/cdesktop, 157 stars), Atlassian MCP Expert (Jeffallan/claude-skills, 12k stars), Notion MCP (LeoYeAI/openclaw-master-skills, 2.2k stars) and Contam MCP (hashgraph-online/awesome-codex-plugins, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Yourdaylight (a GitHub user) maintains it in Yourdaylight/stock_datasource, which has 188 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 8, 2026.
Source: Yourdaylight/stock_datasource on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.