Skip to content

MCPP-AUTHN02: 401 without a Bearer challenge

Family Authentication challenge
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

RFC 6750 §3 requires a WWW-Authenticate: Bearer header on 401 responses. Without it, MCP clients cannot discover where to obtain a token and the authorization flow never starts.

Remediation

Return WWW-Authenticate: Bearer resource_metadata="<PRM URL>", scope="<scopes>" on every 401.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31