reap / rules / auth and session posture
Protected resource does not send a Bearer WWW-Authenticate challenge
mcp-oauth-bearer-challenge-missing ASI03 Identity and Privilege Abuse severity: medium
What it detects
A 401 on tools/list with no WWW-Authenticate: Bearer challenge (RFC 9728/6750), so clients can't discover where to authenticate. ASI03. Emitted by the same probe as mcp-oauth-metadata-posture.
An unauthenticated tools/list returns 401 but the WWW-Authenticate header doesn't include a Bearer challenge (RFC 9728/6750). Emitted by the same probe as mcp-oauth-metadata-posture.
applies to MCP endpoints
Why it matters
Clients cannot discover where to authenticate, so deployments drift toward weaker out-of-band credential handling.
Example finding
MEDIUM mcp-oauth-bearer-challenge-missing HIGH CONFIDENCE Protected resource does not send a Bearer WWW-Authenticate challenge An unauthenticated tools/list request returned 401, but its WWW-Authenticate header did not include a Bearer challenge (got ""). Evidence POST /mcp/gated → 401
from a scan of reap-range, gated target
Fix
Send a WWW-Authenticate: Bearer challenge (optionally with a resource_metadata parameter per RFC 9728) on unauthenticated requests to protected MCP endpoints.
On reap-range
| insecure target | bad/mcp/gated only (401 w/o WWW-Authenticate: Bearer) · Medium |
| correct target | good/mcp 401 includes the challenge |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-oauth-metadata-posture
mcp-oauth-bearer-challenge-missing is reported by the mcp-oauth-metadata-posture probe, so include that.
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.