Type | Description |
API Key | Plaintext key string |
Bearer Token | Bearer token, such as GitHub PAT |
Basic Auth | Username + password. The gateway automatically concatenates them into Authorization: Basic <base64>. |
Custom Header | Custom Header name+value |
Query Param | URL Query parameter name+value |
Parameter | Required | Value Range/Default Value | Description |
Credential Name | Yes | 2-60 characters, unique within the same gateway | Supports uppercase and lowercase letters, digits, and separators ("-", "_"), cannot start with a digit or separator, and cannot end with a separator. |
Credential Type | Yes | API Key/Basic Auth/Bearer Token/Custom Header/Custom Query | - |
API Key Value | Required when the type is APIKey | 8-60 characters | Entered in plaintext and stored encrypted. |
Bearer Token Value | Required when the type is BearerToken | No more than 4096 characters | - |
Username/Password | Required when the type is Basic Auth | Username no more than 256 characters, password no more than 4096 characters | - |
Header Name/Value | Required when the type is Custom Header | Header name must comply with naming conventions and be no more than 128 characters; value must be no more than 4096 characters. | Header name cannot contain :. |
Parameter Name/Value | Required when the type is Custom Query | Query name must comply with naming conventions and be no more than 128 characters; value must be no more than 4096 characters. | - |
Description | No | No more than 200 characters | - |
Parameter | Required | Value Range/Default Value | Description |
Target Resource | Yes | MCP service or tool, supporting batch operations (1 to 50 items) | All resources in a batch operation share the same credential and injection configuration. |
Injection Position | Yes | Header / Query / Body | Default Header |
Injection Field Name | Yes | 1 to 128 characters, such as Authorization and api_key | Injected Header Name/Query Parameter Name/Body Field Path |
Force Overwrite | No, disabled by default | Enable/Disable | When the target is already bound to another credential, enable this option to replace it. |
Authorization)MCP Service Inbound Authentication Method | Verification Result |
API Key | Allow |
JWT / OAuth2.0 | Allow |
OIDC | Blocked. Saving is prohibited. |
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback