TL;DR: Chroma Cloud is a different client mode with different credentials. Set `CHROMA_CLIENT_TYPE=cloud` plus `CHROMA_TENANT`, `CHROMA_DATABASE` and `CHROMA_API_KEY`. A local host/port config will never authenticate against Cloud.

```text
Authentication failed / unauthorized (Chroma Cloud)
```

## Fix it

1. In the Chroma Cloud dashboard, note your tenant, database, and create an API key.

2. Configure the MCP server for cloud mode:

```json
{
  "env": {
    "CHROMA_CLIENT_TYPE": "cloud",
    "CHROMA_TENANT": "your-tenant-id",
    "CHROMA_DATABASE": "your-database-name",
    "CHROMA_API_KEY": "your-api-key"
  }
}
```

   Or the equivalent `--client-type cloud` flags.

3. Restart the MCP client.

   Expected: the server authenticates and collections are visible.

## When to use this

- Connecting the MCP server to Chroma Cloud (`api.trychroma.com`).
- Auth failures with a host/port config pointed at Cloud.

## When NOT to use this

- Local or self-hosted ChromaDB. Cloud variables do nothing there; use host/port or persistent mode.
- 404s on collections with working auth. That is a collection-name problem.

## Compatibility

- chroma-mcp with cloud client support, chroma_mcp_server.
- Chroma Cloud.

## Why it happens

Chroma Cloud authenticates by tenant plus API key, not by host/port. The MCP server picks its client class from `CHROMA_CLIENT_TYPE`. A config written for local HTTP mode builds the wrong client entirely, so nothing about the request looks like valid Cloud auth.

## Edge cases

- Tenant and database are both required. The API key alone is not enough.
- API keys are per-tenant. A key from one tenant fails on another.
- Embedding function API keys (OpenAI etc.) are separate from the Chroma Cloud API key. You may need both.