VectleSkillsElasticsearch MCP: 401 missing authentication credentials (set ES_API_KEY)

Elasticsearch MCP: 401 missing authentication credentials (set ES_API_KEY)

Export

Fixes the Elasticsearch MCP server failing with 401 missing authentication credentials for REST request. The server is reaching Elasticsearch but sending no credentials. The fix is setting ES_API_KEY (or username/password) in the server config. Use when the cluster is reachable but unauthenticated; not for connection errors.

TL;DR: Your MCP server is reaching Elasticsearch but not logging in. Elasticsearch 8 has security on by default and answers every unauthenticated request with 401. Create an API key in Kibana and give it to the MCP server as ES_API_KEY.

{"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]"}]},"status":401}

Fix it

  1. In Kibana, go to Stack Management, Security, API Keys. Create a key. Important: the walkthrough notes that read-only does not include permission to list all indices, so grant the privileges the server needs (superuser works; scope it down if you can).
  1. Copy the encoded key value (the long base64 string), not the raw api_key field.
  1. Set it in the MCP server config. For elastic/mcp-server-elasticsearch:
{
  "env": {
    "ES_URL": "your-cluster",
    "ES_API_KEY": "your-encoded-api-key"
  }
}

Alternatively use ES_USERNAME and ES_PASSWORD with the elastic superuser.

  1. Restart the MCP client.

Expected: tools like list indices and search return data instead of 401.

When to use this

  • Every Elasticsearch tool call fails with 401 missing authentication credentials.
  • curl without auth to the cluster returns the same 401 body (proves the cluster is up and security is on).

When NOT to use this

  • The error is unable to authenticate with credentials set. The key is wrong, expired, or invalidated. Create a new one.
  • The error is 403. Auth worked; the key lacks privileges. Broaden the role descriptors.
  • Connection refused or timeout. The cluster is unreachable.

Compatibility

  • elastic/mcp-server-elasticsearch.
  • Elasticsearch 8.x with security enabled (default), Elastic Cloud, self-hosted.

Why it happens

Elasticsearch 8 enables security by default, unlike older versions that answered anonymously. The MCP server has no credentials unless you configure them, so the first thing it hits is the 401. The error is verbose but the meaning is simple: nobody logged in.

Edge cases

  • Use the encoded value from the API key creation response. The raw api_key plus id pair also works but the encoded form is one string.
  • Invalidated or expired keys fail with unable to authenticate, not missing authentication credentials. Different message, different fix: make a new key.
  • Give each integration its own API key with an expiration, so rotation does not break everything at once.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Elasticsearch+MCP%3A+401+missing+authentication+credentials+%28set+ES_API_KEY%29&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.