Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

EasyAuth returns 403 forbidden

Open
#21 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Bicep
Stars
129
Forks
79
PR merge metrics
No merged PRs in 30d

Description

I have made some changes to try use EasyAuth instead of function key. Copilot suggested using the same app registration so that has been my main attempt. I get everything working except at the very end, it returns 403 when trying to get the list of MCP tools after getting authenticated. The error in the function app:
```
2025-07-18T21:54:34Z [Information] Authorization failed. These requirements were not met:
Handler assertion should evaluate to true.
2025-07-18T21:54:34Z [Information] Executing ForbidResult with authentication schemes (WebJobsAuthLevel, Bearer).
2025-07-18T21:54:34Z [Information] AuthenticationScheme: WebJobsAuthLevel was forbidden.
```

I also made changes to persist the ClientInfo by adding http endpoints to store and fetch the client information. These http endpoints are in the same function app and they do not get rejected. Why do only the MCP endpoints fail the authentication scheme with the exact same token?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.