# Fix: a tools/list without an access token is refused with 401

> Web-audit fix skill for the `mcp-auth-enforced` check (MCP, MAY).

## Goal

Refuse every MCP request that carries no access token with 401.

## Fix

Check the access token before dispatching any JSON-RPC method, `tools/list` included, and answer a
request without one with `401` and the same `WWW-Authenticate` challenge `initialize` receives. A
server that challenges some methods but serves `tools/list` to anyone exposes its tool catalog to
callers that never signed in, and leaves a client unable to tell which calls need a token.

## Resources

- [MCP authorization](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)

## Copy-paste prompt

Paste this into your coding agent. [Your audit](https://anc.dev/audit) adds what it observed for this check:

```text
Goal: Refuse every MCP request that carries no access token with 401
Fix: Check the access token before dispatching any JSON-RPC method, `tools/list` included, and answer a request without one with `401` and the same `WWW-Authenticate` challenge `initialize` receives. A server that challenges some methods but serves `tools/list` to anyone exposes its tool catalog to callers that never signed in, and leaves a client unable to tell which calls need a token.
Skill: https://anc.dev/fix/mcp-auth-enforced
Docs: https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization
```

## Verify

Re-run the audit at [https://anc.dev/audit](https://anc.dev/audit) or call the `audit_website` MCP tool; the `mcp-auth-enforced` check should report `pass`.
