diff --git a/backend/Middleware/ApiKeyMiddleware.cs b/backend/Middleware/ApiKeyMiddleware.cs index 5ab1c6f..69d21fa 100644 --- a/backend/Middleware/ApiKeyMiddleware.cs +++ b/backend/Middleware/ApiKeyMiddleware.cs @@ -6,11 +6,23 @@ namespace Nexus.Api.Middleware; /// Middleware that authenticates requests via the X-Nexus-Api-Key header. /// On match, sets a ClaimsPrincipal with role "Service". /// On mismatch or absent header, passes through to next middleware (JWT auth). +/// +/// The MCP endpoint (/mcp) is intentionally skipped — the MCP SDK handles its own +/// authentication via X-Agent-Id + X-Nexus-Api-Key headers through NexusMcpTools. /// public sealed class ApiKeyMiddleware(RequestDelegate next) { + private static readonly PathString McpPath = new("/mcp"); + public async Task InvokeAsync(HttpContext context) { + // MCP endpoint handles its own auth — skip ApiKey interference + if (context.Request.Path.StartsWithSegments(McpPath)) + { + await next(context); + return; + } + var configuration = context.RequestServices.GetRequiredService(); var apiKey = configuration["NexusApiKey"];