MCPP-AUTHN05: Error code in an unauthenticated challenge¶
| Family | Authentication challenge |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
RFC 6750 §3.1: when a request carries no authentication, the resource server SHOULD NOT include an error code. Doing so leaks validation details and confuses clients that treat invalid_token as a reason to drop credentials.
Remediation¶
Return a bare Bearer challenge (realm, resource_metadata, scope) when no token was sent; reserve error= for requests that included a token.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31