MCPP-AUTHN02: 401 without a Bearer challenge¶
| Family | Authentication challenge |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
RFC 6750 §3 requires a WWW-Authenticate: Bearer header on 401 responses. Without it, MCP clients cannot discover where to obtain a token and the authorization flow never starts.
Remediation¶
Return WWW-Authenticate: Bearer resource_metadata="<PRM URL>", scope="<scopes>" on every 401.
References¶
- RFC 6750 Bearer Token Usage
- MCP 2025-06-18 Authorization
- RFC 9728 §5.1 WWW-Authenticate resource_metadata
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31