Chroma MCP: Chroma Cloud auth failed (set tenant, database and API key)
Fixes the Chroma MCP server failing against Chroma Cloud with auth errors. Cloud mode needs CHROMA_TENANT, CHROMA_DATABASE and CHROMA_API_KEY, which local-mode configs lack. The fix is setting all three and using cloud client type. Use when connecting to Chroma Cloud; not for local instances.
TL;DR: Chroma Cloud is a different client mode with different credentials. Set CHROMA_CLIENT_TYPE=cloud plus CHROMA_TENANT, CHROMA_DATABASE and CHROMA_API_KEY. A local host/port config will never authenticate against Cloud.
Authentication failed / unauthorized (Chroma Cloud)Fix it
- In the Chroma Cloud dashboard, note your tenant, database, and create an API key.
- Configure the MCP server for cloud mode:
{
"env": {
"CHROMA_CLIENT_TYPE": "cloud",
"CHROMA_TENANT": "your-tenant-id",
"CHROMA_DATABASE": "your-database-name",
"CHROMA_API_KEY": "your-api-key"
}
} Or the equivalent --client-type cloud flags.
- Restart the MCP client.
Expected: the server authenticates and collections are visible.
When to use this
- Connecting the MCP server to Chroma Cloud (
api.trychroma.com). - Auth failures with a host/port config pointed at Cloud.
When NOT to use this
- Local or self-hosted ChromaDB. Cloud variables do nothing there; use host/port or persistent mode.
- 404s on collections with working auth. That is a collection-name problem.
Compatibility
- chroma-mcp with cloud client support, chromamcpserver.
- Chroma Cloud.
Why it happens
Chroma Cloud authenticates by tenant plus API key, not by host/port. The MCP server picks its client class from CHROMA_CLIENT_TYPE. A config written for local HTTP mode builds the wrong client entirely, so nothing about the request looks like valid Cloud auth.
Edge cases
- Tenant and database are both required. The API key alone is not enough.
- API keys are per-tenant. A key from one tenant fails on another.
- Embedding function API keys (OpenAI etc.) are separate from the Chroma Cloud API key. You may need both.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.