---
summary: "Breaking: OPENALEX_API_KEY now authenticates as api_key= (the old mailto= was ignored) — an email previously set there must move to the new OPENALEX_MAILTO; mcp-ts-core ^0.10.14 supply-chain guard adopted."
breaking: true
security: false
---

# 0.7.3 — 2026-07-09

> ⚠️ **Breaking for existing setups.** `OPENALEX_API_KEY` now goes upstream as `api_key=`, not the previously-ignored `mailto=`. If you had set it to an **email address** (the old polite-pool convention), OpenAlex will now reject it as an invalid key (HTTP 401). Move the email to the new `OPENALEX_MAILTO`, and set `OPENALEX_API_KEY` to a real [account key](https://openalex.org/settings/api) or leave it unset for anonymous access. See Migration below.

## Added

- **`OPENALEX_MAILTO`** — optional email sent upstream as `mailto=` to identify yourself to OpenAlex (the polite pool), decoupled from the account credential.

## Changed

- **`Dockerfile`** — pinned to `oven/bun:1.3.14`; build stage adds `--ignore-scripts` and a BuildKit cache mount for Bun's install cache.
- **Skills** — 12 skills re-synced from mcp-ts-core (`add-tool`, `api-canvas`, `api-linter`, `api-utils`, `api-workers`, `code-simplifier`, `design-mcp-server`, `git-wrapup`, `orchestrations`, `polish-docs-meta`, `release-and-publish`, `techniques`).

## Fixed

- **`OPENALEX_API_KEY` now authenticates upstream** — sent as `api_key=` instead of the ignored `mailto=`, so a configured key actually authenticates under OpenAlex's usage-based pricing. ([#47](https://github.com/cyanheads/openalex-mcp-server/issues/47))
- **`api_key` redacted from surfaced error URLs** — the caller-param allowlist in `url-redaction.ts` strips it (and `mailto`) from any URL that reaches an MCP client via a thrown error.
- **Unauthorized recovery hint corrected** — all 4 tools' `upstream_unauthorized` contract now points to a real OpenAlex account API key instead of the old "email-format key" wording.

**Migration:** `OPENALEX_API_KEY` must now be an OpenAlex account API key (free from [openalex.org/settings/api](https://openalex.org/settings/api)), sent as `api_key=`. If you previously placed an email address there for polite-pool identification, move it to the new `OPENALEX_MAILTO` above.

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.10.9 → ^0.10.14 — adopts the 0.10.13 supply-chain guard: `bunfig.toml` Socket scanner (`@socketsecurity/bun-security-scanner`) plus `minimumReleaseAge` (3-day hold on freshly published packages, excluding same-day framework releases), a new `.github/SECURITY.md`, and a new `.gitattributes`.
- Transitive bumps via the lock re-resolve: `js-yaml`, `vite`, `hono`. `bun audit` reports zero vulnerabilities.
