VectleSkillsQdrant MCP: 401 Unauthorized (set QDRANT_API_KEY for key-protected Qdrant)

Qdrant MCP: 401 Unauthorized (set QDRANT_API_KEY for key-protected Qdrant)

Export

Fixes the Qdrant MCP server getting HTTP 401 Unauthorized from a Qdrant instance that requires an API key. The server sends no key because QDRANT_API_KEY was never set. The fix is setting QDRANT_API_KEY in the client env block. Use when Qdrant requires a key and the server does not send one; not for connection errors.

TL;DR: HTTP 401 from Qdrant means the instance requires an API key and the MCP server is not sending one. Set QDRANT_API_KEY in the client config env block next to QDRANT_URL. Qdrant Cloud always needs this.

HTTP 401 Unauthorized

(From the Qdrant instance, surfaced through the MCP server's tools.)

Fix it

  1. Confirm the key requirement. Test with curl:
curl -H "api-key value YOUR_KEY" https://your-cluster.qdrant.io:6333/collections

Expected: JSON. Without the header you get 401, proving the key is required.

  1. Get the API key: Qdrant Cloud dashboard for cloud clusters, or the value of QDRANT__SERVICE__API_KEY for self-hosted.
  1. Set it in the client config:
{
  "mcpServers": {
    "qdrant": {
      "env": {
        "QDRANT_URL": "https://your-cluster.qdrant.io:6333",
        "QDRANT_API_KEY": "your-api-key-here"
      }
    }
  }
}
  1. Restart the MCP client.

Expected: 401 is gone, tools work.

When to use this

  • Tools fail with 401 or Unauthorized against Qdrant Cloud or a key-protected self-hosted instance.
  • The curl test without the key also 401s.

When NOT to use this

  • The error is connection refused. Qdrant is not reachable at all.
  • Local Qdrant without a key set. Then no key is needed; check the URL.

Compatibility

  • qdrant/mcp-server-qdrant and Qdrant-backed MCP servers that honor QDRANTAPIKEY.
  • Qdrant Cloud, self-hosted Qdrant with QDRANTSERVICEAPI_KEY.

Why it happens

Qdrant's API key gate rejects every keyless request with 401. MCP servers that predate key support (or configs copied from keyless local setups) send nothing, so everything 401s. Qdrant Cloud always requires a key, which surprises people moving from local Docker.

Edge cases

  • The key travels as the api-key header. It is never logged by well-behaved servers, but do not paste it into chats anyway.
  • Sending a key over plain http:// triggers a client warning. Use https:// for key-protected instances.
  • If you set the key server-side, the /collections healthcheck also needs it. Use /readyz for unauthenticated health checks.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Qdrant+MCP%3A+401+Unauthorized+%28set+QDRANT_API_KEY+for+key-protected+Qdrant%29&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.