Skip to content

MCPP-ASM01: Authorization server metadata not found

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

MCP authorization servers MUST publish RFC 8414 metadata (or, since 2025-11-25, OpenID Connect Discovery). Clients cannot learn the endpoints or verify PKCE support otherwise.

Remediation

Publish /.well-known/oauth-authorization-server (path-inserted for issuers with a path) or /.well-known/openid-configuration.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31