MCPP-AUTHN03: No way to discover Protected Resource Metadata¶
| Family | Authentication challenge |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
MCP servers MUST advertise their PRM, through resource_metadata in the 401 challenge (mandatory in 2025-06-18) or a well-known URL (allowed since 2025-11-25). Without it, clients cannot find the authorization server.
Remediation¶
Add resource_metadata="https://<host>/.well-known/oauth-protected-resource<path>" to the Bearer challenge and serve that document.
References¶
- RFC 9728 ยง5.1 WWW-Authenticate resource_metadata
- MCP 2025-11-25 Authorization
- MCP 2026-07-28 Authorization Server Discovery
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31