Skip to content

MCPP-SCP02: Challenge does not name the required scope

Family Scopes
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions 2025-11-25 and later

Why it matters

Since 2025-11-25 servers SHOULD include scope in the 401 challenge so clients request exactly what the operation needs, instead of every scope in scopes_supported.

Remediation

Add scope="<scopes>" to the WWW-Authenticate: Bearer challenge.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-SCP02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31