Qdrant MCP: 401 Unauthorized (set QDRANT_API_KEY for key-protected Qdrant)
Fixes the Qdrant MCP server getting HTTP 401 Unauthorized from a Qdrant instance that requires an API key. The server sends no key because QDRANT_API_KEY was never set. The fix is setting QDRANT_API_KEY in the client env block. Use when Qdrant requires a key and the server does not send one; not for connection errors.
TL;DR: HTTP 401 from Qdrant means the instance requires an API key and the MCP server is not sending one. Set QDRANT_API_KEY in the client config env block next to QDRANT_URL. Qdrant Cloud always needs this.
HTTP 401 Unauthorized(From the Qdrant instance, surfaced through the MCP server's tools.)
Fix it
- Confirm the key requirement. Test with curl:
curl -H "api-key value YOUR_KEY" https://your-cluster.qdrant.io:6333/collectionsExpected: JSON. Without the header you get 401, proving the key is required.
- Get the API key: Qdrant Cloud dashboard for cloud clusters, or the value of
QDRANT__SERVICE__API_KEYfor self-hosted.
- Set it in the client config:
{
"mcpServers": {
"qdrant": {
"env": {
"QDRANT_URL": "https://your-cluster.qdrant.io:6333",
"QDRANT_API_KEY": "your-api-key-here"
}
}
}
}- Restart the MCP client.
Expected: 401 is gone, tools work.
When to use this
- Tools fail with 401 or Unauthorized against Qdrant Cloud or a key-protected self-hosted instance.
- The curl test without the key also 401s.
When NOT to use this
- The error is connection refused. Qdrant is not reachable at all.
- Local Qdrant without a key set. Then no key is needed; check the URL.
Compatibility
- qdrant/mcp-server-qdrant and Qdrant-backed MCP servers that honor QDRANTAPIKEY.
- Qdrant Cloud, self-hosted Qdrant with QDRANTSERVICEAPI_KEY.
Why it happens
Qdrant's API key gate rejects every keyless request with 401. MCP servers that predate key support (or configs copied from keyless local setups) send nothing, so everything 401s. Qdrant Cloud always requires a key, which surprises people moving from local Docker.
Edge cases
- The key travels as the
api-keyheader. It is never logged by well-behaved servers, but do not paste it into chats anyway. - Sending a key over plain
http://triggers a client warning. Usehttps://for key-protected instances. - If you set the key server-side, the
/collectionshealthcheck also needs it. Use/readyzfor unauthenticated health checks.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.