MCP-AUT-001
Unauthenticated request returns 401 with WWW-Authenticate resource_metadata
“HTTP/1.1 401 Unauthorized. WWW-Authenticate: Bearer resource_metadata="https://mcp.example.com/.well-known/oauth-protected-resource".” — spec anchor
How to fix this
Return 401 with `WWW-Authenticate: Bearer resource_metadata="https://your-server/.well-known/oauth-protected-resource"`. A bare 401 is a dead end — the client has nowhere to go and authenticate.
How the validator checks this
Probe P8.1, against a streamable-http server on the modern protocol. What it reports:
- pass
- 401 carried WWW-Authenticate with resource_metadata="…"
- fail
- 401 without a WWW-Authenticate resource_metadata parameter (header: …). A bare 401 is a dead end — the client has nowhere to authenticate.
Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.
This rule is checked deterministically: a fail here is a certain violation, not an inference.
Checked in the same request as MCP-AUT-006, MCP-AUT-007, MCP-AUT-008, MCP-SEC-007.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Authorization rules
- MCP-AUT-002RFC 9728 Protected Resource Metadata is served and valid
- MCP-AUT-003PRM resource equals the canonical server URI
- MCP-AUT-004Each listed authorization server exposes RFC 8414 or OIDC discovery metadata
- MCP-AUT-005AS advertises authorization_response_iss_parameter_supported: true
- MCP-AUT-006WWW-Authenticate includes a scope parameter
- MCP-AUT-007Insufficient scope returns 403 with error="insufficient_scope"
- MCP-AUT-008Tokens with a foreign audience are rejected
- MCP-AUT-009offline_access absent from scopes_supported / challenge scope
- MCP-AUT-010AS advertises S256 in code_challenge_methods_supported
- MCP-AUT-011AS supports Client ID Metadata Documents, not DCR alone