Fix: a tools/list without an access token is refused with 401

Web-audit fix skill for the mcp-auth-enforced check (MCP, MAY).

Goal

Refuse every MCP request that carries no access token with 401.

Fix

Check the access token before dispatching any JSON-RPC method, tools/list included, and answer a request without one with 401 and the same WWW-Authenticate challenge initialize receives. A server that challenges some methods but serves tools/list to anyone exposes its tool catalog to callers that never signed in, and leaves a client unable to tell which calls need a token.

Resources

Copy-paste prompt

Paste this into your coding agent. Your audit adds what it observed for this check:

Verify

Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-enforced check should report pass.