Fix: a 401 names the RFC 9728 metadata in its WWW-Authenticate challenge
Web-audit fix skill for the
mcp-auth-challengecheck (MCP, MAY).
Goal
Name your protected-resource metadata in the WWW-Authenticate challenge of every 401.
Fix
When the MCP endpoint refuses a request that carries no access token, answer 401 with WWW-Authenticate: Bearer resource_metadata="https://<host>/.well-known/oauth-protected-resource", naming the URL of your RFC 9728 metadata. A client reads the challenge to find the authorization server; without resource_metadata it falls back to guessing well-known locations. The MCP authorization specification requires the header on every 401.
Resources
Copy-paste prompt
Paste this into your coding agent. Your audit adds what it observed for this check:
Verify
Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-challenge check should report pass.