API Keys¶
Most BioMCP workflows run without credentials. Some enrichment and higher-rate access paths improve with API keys. For provider terms, redistribution caveats, and which sources are only indirect provenance, see the source-licensing reference.
Required for prediction section¶
ALPHAGENOME_API_KEY¶
Used by variant prediction lookups:
Provider access: https://deepmind.google/science/alphagenome/
Required for exact ORCID author records¶
ORCID_ACCESS_TOKEN¶
Used by biomcp get author orcid:<id> and biomcp author papers orcid:<id> to
read the public ORCID record. Obtain a public-read bearer token for the
/read-public scope from ORCID. Percent-encode the scope as %2Fread-public
when you submit the token form; ORCID rejects the raw slash in the scope
field.
Public ORCID records are readable without any token. The token is a quota measure: it moves requests from the shared anonymous pool onto a dedicated rate limit.
Provider access: https://info.orcid.org/documentation/features/public-api/
Additional API keys¶
ONCOKB_TOKEN¶
Used for the production biomcp variant oncokb ... helper. Without the
token, that helper is unavailable and reports the required environment
variable.
BioMCP keeps ONCOKB_TOKEN because OncoKB itself calls the credential a
token.
Register at: https://www.oncokb.org/account/register
NCI_API_KEY¶
Used for NCI CTS trial calls.
Request access at: https://clinicaltrialsapi.cancer.gov/
DISGENET_API_KEY¶
Required for DisGeNET scored association sections on genes and diseases. Without the key, those DisGeNET sections are unavailable and report the required environment variable. A configured key may still be rejected if it is invalid or if the account's plan lacks access; check the credential and account access rather than exporting the variable again.
Register at: https://www.disgenet.com/
export DISGENET_API_KEY="..."
biomcp get gene TP53 disgenet
biomcp get disease "breast cancer" disgenet
UMLS_API_KEY¶
Adds optional clinical crosswalk enrichment to biomcp discover. Without the
key, discover still runs with OLS4-only results and omits UMLS crosswalks.
Register at: https://uts.nlm.nih.gov/uts/signup-login
NCBI_API_KEY¶
Improves rate limits for ClinVar EFetch, PubTator, PubMed/efetch, PMC OA, and NCBI ID converter (3 → 10 req/sec).
Create one in My NCBI: https://www.ncbi.nlm.nih.gov/account/settings/
S2_API_KEY¶
Enables authenticated Semantic Scholar article requests. Use it for a dedicated
provider quota at 1 req/sec across the optional article search leg, get article
enrichment, get article ... tldr, article citations, article references,
and article recommendations. Without the key, those paths still work through
the shared unauthenticated pool at 1 req/2sec.
BioMCP sends x-api-key only to the canonical Semantic Scholar HTTPS API
origin. A noncanonical BIOMCP_S2_BASE override is unauthenticated, and the key
cannot follow a redirect to another origin. The internal exact-origin fixture
signal used by repository tests is the only unsafe local exception; it is not a
CLI or model argument.
Request a key at: https://www.semanticscholar.org/product/api
export S2_API_KEY="..."
biomcp get article 22663011 tldr
biomcp article citations 22663011 --limit 3
OPENFDA_API_KEY¶
Improves OpenFDA rate limits for drug safety lookups.
Request a key at: https://open.fda.gov/apis/authentication/
Key management guidance¶
- Prefer environment variables over hardcoded values.
- Do not commit secrets into source control.
- Set keys in the same environment used by your MCP client.
- Rotate keys when sharing machines or CI runners.
S2_API_KEYis optional. Without it, article search/get/helper paths still work through the shared Semantic Scholar pool at 1 req/2sec. With it, BioMCP sendsx-api-keyonly to the approved canonical Semantic Scholar origin and uses the authenticated quota at 1 req/sec for those requests.UMLS_API_KEYis optional; when absent,discoverstill works with OLS4-only results.
See also: Source Licensing and Terms