---
summary: "Stop sending Basic auth to keyless GBIF API; remove GBIF_API_KEY"
breaking: false
security: false
---

# 0.2.3 — 2026-05-28

## Fixed

- **Basic auth removed from all GBIF requests** — the service was constructing `Authorization: Basic base64(GBIF_API_KEY + ":")` and sending it on every request. GBIF's public REST API is keyless; it validated the credential as a real GBIF.org account credential, found it invalid, and returned HTTP 401. The rejection was intermittent for cacheable paths but consistent on `/occurrence/search`, breaking `gbif_search_occurrences` and `gbif_occurrence_facets`. The `buildHeaders()` method and its auth-injection branch are removed; requests now send only `Accept: application/json`. (#18)

## Removed

- **`GBIF_API_KEY` env var** — the env var, its Zod schema field, `parseEnvConfig` mapping, constructor option, and `authHeader` private field are all gone. The public GBIF REST API has no API-key tier; the premise was incorrect. Update any `.env` files or deployment configs that set this variable — it is silently ignored now (the config parser no longer maps it) and can be safely removed.
