Fix: a tools/list without an access token is refused with 401
Web-audit fix skill for the
mcp-auth-enforcedcheck (MCP, MAY).
Goal
Refuse every MCP request that carries no access token with 401.
Fix
Check the access token before dispatching any JSON-RPC method, tools/list included, and answer a request without one with 401 and the same WWW-Authenticate challenge initialize receives. A server that challenges some methods but serves tools/list to anyone exposes its tool catalog to callers that never signed in, and leaves a client unable to tell which calls need a token.
Resources
Copy-paste prompt
Paste this into your coding agent. Your audit adds what it observed for this check:
Verify
Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-enforced check should report pass.