Fix: a 401 names the RFC 9728 metadata in its WWW-Authenticate challenge

Web-audit fix skill for the mcp-auth-challenge check (MCP, MAY).

Goal

Name your protected-resource metadata in the WWW-Authenticate challenge of every 401.

Fix

When the MCP endpoint refuses a request that carries no access token, answer 401 with WWW-Authenticate: Bearer resource_metadata="https://<host>/.well-known/oauth-protected-resource", naming the URL of your RFC 9728 metadata. A client reads the challenge to find the authorization server; without resource_metadata it falls back to guessing well-known locations. The MCP authorization specification requires the header on every 401.

Resources

Copy-paste prompt

Paste this into your coding agent. Your audit adds what it observed for this check:

Verify

Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-challenge check should report pass.