TL;DR: Weaviate Cloud requires an API key and your MCP server is not sending one. Set `WEAVIATE_API_KEY` in the server's environment alongside `WEAVIATE_URL`. Local Docker Weaviate does not need this, which is why the same config breaks when you move to Cloud.

```text
401 Unauthorized
```

(From Weaviate Cloud, surfaced through the MCP server's tools.)

## Fix it

1. In the Weaviate Cloud dashboard, create an API key for your cluster. Copy it.

2. Set both variables in the MCP client config `env` block:

```json
{
  "env": {
    "WEAVIATE_URL": "https://your-cluster.weaviate.cloud",
    "WEAVIATE_API_KEY": "your-weaviate-api-key"
  }
}
```

3. Restart the MCP client.

   Expected: 401 is gone, collection tools work.

## When to use this

- Tools fail with 401 against a `*.weaviate.cloud` URL.
- The same config works against local Docker Weaviate.

## When NOT to use this

- Local Docker Weaviate with auth disabled. No key is needed; check the URL.
- Connection refused or timeout. The instance is unreachable.

## Compatibility

- weaviate/mcp-server-weaviate and Weaviate-backed MCP servers.
- Weaviate Cloud.

## Why it happens

Weaviate Cloud mandates API key auth on every request. Local Docker images ship with auth off for convenience. Configs migrate from local to Cloud carrying only the URL, and the missing key produces a bare 401 with no hint about what to set.

## Edge cases

- The Cloud URL is `https://`. Plain `http://` fails differently.
- API keys are per-cluster. A key for cluster A does not work on cluster B.
- If you enabled auth on self-hosted Weaviate (APIKEY auth), the same variable applies. Check how your server maps it.