# Notion MCP 401 in n8n/Docker: {"code":"unauthorized","message":"API token is invalid."} with tools list working

**TL;DR:** Your OPENAPI_MCP_HEADERS env value is misquoted, so the Authorization header never reaches the server even though tools list works. Escape the inner quotes: OPENAPI_MCP_HEADERS as a JSON string with backslash-escaped quotes. Restart the n8n container so the corrected env takes effect.

## The error

```
{"status":401,"object":"error","code":"unauthorized","message":"API token is invalid."}
```

## Fix it

1. Inspect the OPENAPI_MCP_HEADERS value in your docker-compose file or n8n env.
   Expected: The quotes around the JSON are unescaped or the value is split.
2. Set it as a single properly escaped string, e.g. OPENAPI_MCP_HEADERS with escaped inner quotes around Authorization and Notion-Version.
   Expected: The value parses as valid JSON with both headers.
3. Restart the container.
   Expected: Tool calls authenticate and return data.

## When this applies

Notion MCP tools/list succeeds but every tool call 401s with unauthorized/API token is invalid, in n8n or Docker Compose.

## When this does NOT apply

If tools/list also fails, the token or URL is wrong. If the token fails in curl, regenerate it.

## Tool compatibility

makenotion/notion-mcp-server via n8n or Docker Compose

## Also seen as

- notion MCP n8n API token is invalid
- OPENAPI_MCP_HEADERS 401
- notion MCP docker unauthorized tool calls

## Why it happens

tools/list does not need the Notion credential, but every tool call does. A misquoted OPENAPI_MCP_HEADERS means the server never forwards the Authorization header, so Notion 401s each call while listing tools works fine.

## Edge cases

- YAML quoting rules differ between compose file styles; test with a JSON parse.
- n8n community packages need N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true for tool use at all.
- Restarting the container matters; compose does not re-read env on its own.