# Fix: a 401 names the RFC 9728 metadata in its WWW-Authenticate challenge

> Web-audit fix skill for the `mcp-auth-challenge` check (MCP, MAY).

## Goal

Name your protected-resource metadata in the WWW-Authenticate challenge of every 401.

## Fix

When the MCP endpoint refuses a request that carries no access token, answer `401` with
`WWW-Authenticate: Bearer resource_metadata="https://<host>/.well-known/oauth-protected-resource"`,
naming the URL of your RFC 9728 metadata. A client reads the challenge to find the authorization
server; without `resource_metadata` it falls back to guessing well-known locations. The MCP
authorization specification requires the header on every `401`.

## Resources

- [MCP authorization](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)
- [RFC 9728 section 5.1](https://www.rfc-editor.org/rfc/rfc9728#section-5.1)

## Copy-paste prompt

Paste this into your coding agent. [Your audit](https://anc.dev/audit) adds what it observed for this check:

```text
Goal: Name your protected-resource metadata in the WWW-Authenticate challenge of every 401
Fix: When the MCP endpoint refuses a request that carries no access token, answer `401` with `WWW-Authenticate: Bearer resource_metadata="https://<host>/.well-known/oauth-protected-resource"`, naming the URL of your RFC 9728 metadata. A client reads the challenge to find the authorization server; without `resource_metadata` it falls back to guessing well-known locations. The MCP authorization specification requires the header on every `401`.
Skill: https://anc.dev/fix/mcp-auth-challenge
Docs: https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization, https://www.rfc-editor.org/rfc/rfc9728#section-5.1
```

## Verify

Re-run the audit at [https://anc.dev/audit](https://anc.dev/audit) or call the `audit_website` MCP tool; the `mcp-auth-challenge` check should report `pass`.
