Mira Vantis

How do you know if your MCP server is exposed?

Check three things. If tools/list answers without a token, if a request with no token doesn't get a 401 with a WWW-Authenticate header, or if the server forwards your token to other APIs, it's exposed. Trend Micro found 492 MCP servers with no client authentication, exposing 1,402 tools.

Posted Oct 7, 2026

The breakdown

Red flag one: tools/list works without logging in

If anyone can list your tools without a token, anyone can call them too. Trend Micro found 492 MCP servers running with no client authentication or traffic encryption, exposing 1,402 tools. It says more than 90% of them offered direct read access to the data source.

Red flag two: no 401 with a WWW-Authenticate header

The MCP specification (2025-06-18) says a protected server must return 401 Unauthorized with a WWW-Authenticate header that points to its protected resource metadata, as defined in RFC 9728. If you get a 200, or a bare 401, auth isn't set up the way clients expect.

Red flag three: it passes your token upstream

The spec says an MCP server must not pass through the token it got from the client, and must only accept tokens issued for it. A server that forwards your token to another API lets a caller act with your access. That's the confused deputy problem.

Green flag

Authentication sits in front of the server, at a gateway, so every request is checked before it reaches a tool.

A quick check

Send a tools/list request to your server with no Authorization header. You want a 401 and a WWW-Authenticate header that names a resource_metadata URL. Anything else is worth a closer look.

The question at the end of the video: Which of the three red flags would your server fail?

Sources

  1. Trend Micro: MCP Security: Network-Exposed Servers Are Backdoors to Your Private Data (Jul 2025)
  2. Model Context Protocol specification 2025-06-18: Authorization
  3. RFC 9728: OAuth 2.0 Protected Resource Metadata

FAQ

What is an MCP server?

An MCP server exposes tools and data to AI agents over the Model Context Protocol. An agent calls tools/list to see what it can do, then calls those tools. If the server has no auth, anyone who can reach it can do the same.

Does an MCP server need authentication?

Any MCP server reachable over a network should require it. The MCP specification says a protected server returns 401 with a WWW-Authenticate header and only accepts tokens issued for it.

What is token passthrough in MCP?

Token passthrough is when an MCP server takes the token a client sent it and forwards that same token to another API. The MCP specification forbids it, because it lets a caller borrow access the server was never meant to grant.

How do I test my MCP server for open access?

Send a tools/list request with no Authorization header. A properly protected server returns 401 with a WWW-Authenticate header. If you get the tool list back, the server is open.

More clips