
# Endpoint and authentication

Your AI client needs two things: the server URL and your AccuWeather API key. One URL covers every tool.

```text
https://dataservice.accuweather.com/mcp
```

Get started by providing the server URL above and your API key. See [client connection](/documentation/weather-mcp-client-connection) for instructions.

## Authentication

Use the same key you use for the REST API. There is nothing extra to sign up for and no second credential to manage. Your keys are on the [subscriptions page](/subscriptions).

The key has to be on the free trial or the Elite plan. If something is wrong, your client will show one of these:

| Response           | What it means                                                                                    |
| ------------------ | ------------------------------------------------------------------------------------------------ |
| `401 Unauthorized` | The key is missing, mistyped, or no longer active.                                               |
| `403 Forbidden`    | The key works, but its plan does not include MCP. Compare plans on the [pricing page](/pricing). |

:::info{title="Your assistant never sees the key"}

You enter the key once, in your client, and it authenticates the connection itself. The assistant using that connection cannot see your key, ask anyone for it, or repeat it back in a conversation.

:::

### Send the key

There are two methods to send your API key. Most clients provide a field for a header. In that case, use:

```http
Authorization: Bearer YOUR_API_KEY
```

Some clients only let you paste a URL, with nowhere to put a header. For those, add your key to the URL as an `apikey` parameter instead:

```text
https://dataservice.accuweather.com/mcp?apikey=YOUR_API_KEY
```

Either method works, but we recommend using the header when your client offers the option.

:::warning{title="Treat a URL with your key in it as a secret"}

Including your API key directly in the URL means your API key is visible any time the URL is visible.

- Do not commit it to a code repository, paste it into a ticket or chat, or include it in a screenshot.
- Expect it to be recorded in browser history, server access logs, and proxy logs.
- Rotate the key on the [subscriptions page](/subscriptions) if a URL containing it gets out.

:::

### If your client asks for OAuth

Some MCP clients assume every remote server signs users in through OAuth, so they ask for a client ID and client secret, or try to open a sign-in page. AccuWeather uses an API key instead, so there is nothing to enter and no sign-in page.

If your client's guided setup requires OAuth, skip the setup and manually enter the server URL and header. See [Client connection](/documentation/weather-mcp-client-connection) for help.

## What next?

- [Client connection](/documentation/weather-mcp-client-connection) — setup examples for common MCP clients
- [Tools](/documentation/weather-mcp-tools) — what you can call once you are connected
- [Authentication](/documentation/authentication) — how API keys work across all AccuWeather APIs
