Weaviate MCP: 401 Unauthorized on Weaviate Cloud (set WEAVIATE_API_KEY)
Fixes the Weaviate MCP server failing with 401 Unauthorized against Weaviate Cloud. The server is not sending an API key because WEAVIATE_API_KEY was never set. The fix is setting WEAVIATE_API_KEY in the server env. Use when connecting to Weaviate Cloud; not for local Docker instances without auth.
TL;DR: Weaviate Cloud requires an API key and your MCP server is not sending one. Set WEAVIATE_API_KEY in the server's environment alongside WEAVIATE_URL. Local Docker Weaviate does not need this, which is why the same config breaks when you move to Cloud.
401 Unauthorized(From Weaviate Cloud, surfaced through the MCP server's tools.)
Fix it
- In the Weaviate Cloud dashboard, create an API key for your cluster. Copy it.
- Set both variables in the MCP client config
envblock:
{
"env": {
"WEAVIATE_URL": "https://your-cluster.weaviate.cloud",
"WEAVIATE_API_KEY": "your-weaviate-api-key"
}
}- Restart the MCP client.
Expected: 401 is gone, collection tools work.
When to use this
- Tools fail with 401 against a
*.weaviate.cloudURL. - The same config works against local Docker Weaviate.
When NOT to use this
- Local Docker Weaviate with auth disabled. No key is needed; check the URL.
- Connection refused or timeout. The instance is unreachable.
Compatibility
- weaviate/mcp-server-weaviate and Weaviate-backed MCP servers.
- Weaviate Cloud.
Why it happens
Weaviate Cloud mandates API key auth on every request. Local Docker images ship with auth off for convenience. Configs migrate from local to Cloud carrying only the URL, and the missing key produces a bare 401 with no hint about what to set.
Edge cases
- The Cloud URL is
https://. Plainhttp://fails differently. - API keys are per-cluster. A key for cluster A does not work on cluster B.
- If you enabled auth on self-hosted Weaviate (APIKEY auth), the same variable applies. Check how your server maps it.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.