Skip to content

MCPP-AUTHN01: MCP tools listed without authentication

Family Authentication challenge
Default severity high
Confidence medium
Mode passive (default scan)
Spec revisions all

Why it matters

Anyone who can reach the endpoint can enumerate (and likely call) the server's tools. Some servers are public on purpose, hence medium confidence; for anything that touches user or company data this is an authentication bypass.

Remediation

Require an OAuth access token on every MCP request (return 401 with a WWW-Authenticate: Bearer resource_metadata=... challenge), or document the server as intentionally public and suppress this finding with a justification.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31