hackwither_

reap / rules / auth and session posture

Protected resource does not send a Bearer WWW-Authenticate challenge

mcp-oauth-bearer-challenge-missing ASI03 Identity and Privilege Abuse severity: medium

What it detects

A 401 on tools/list with no WWW-Authenticate: Bearer challenge (RFC 9728/6750), so clients can't discover where to authenticate. ASI03. Emitted by the same probe as mcp-oauth-metadata-posture.

An unauthenticated tools/list returns 401 but the WWW-Authenticate header doesn't include a Bearer challenge (RFC 9728/6750). Emitted by the same probe as mcp-oauth-metadata-posture.

applies to MCP endpoints

Why it matters

Clients cannot discover where to authenticate, so deployments drift toward weaker out-of-band credential handling.

OWASP ASI mapping rationale

Example finding

MEDIUM  mcp-oauth-bearer-challenge-missing  HIGH CONFIDENCE
Protected resource does not send a Bearer WWW-Authenticate challenge
An unauthenticated tools/list request returned 401, but its WWW-Authenticate header did not include a Bearer challenge (got "").
Evidence  POST /mcp/gated → 401

from a scan of reap-range, gated target

Fix

Send a WWW-Authenticate: Bearer challenge (optionally with a resource_metadata parameter per RFC 9728) on unauthenticated requests to protected MCP endpoints.

On reap-range

insecure targetbad/mcp/gated only (401 w/o WWW-Authenticate: Bearer) · Medium
correct targetgood/mcp 401 includes the challenge

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-oauth-metadata-posture

mcp-oauth-bearer-challenge-missing is reported by the mcp-oauth-metadata-posture probe, so include that.

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.