Embedding the API key (secret) in the URL complicates secret management. Please move that to a header and allow setting via env var.
I would say the /apiKey/mcp integration path is more tailored for manual Claude Desktop / VS Code users where it might be easier, than trying to insert headers somehow.
Regarding the environment variables, the MCP is stateless so the secret management is handled on the client and obviously it could be set via env vars.