Skip to content

MCPP-AUTHN03: No way to discover Protected Resource Metadata

Family Authentication challenge
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

MCP servers MUST advertise their PRM, through resource_metadata in the 401 challenge (mandatory in 2025-06-18) or a well-known URL (allowed since 2025-11-25). Without it, clients cannot find the authorization server.

Remediation

Add resource_metadata="https://<host>/.well-known/oauth-protected-resource<path>" to the Bearer challenge and serve that document.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31