Skip to content

MCPP-ASM02: Issuer mismatch

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

The issuer in the metadata MUST be identical to the issuer used to build the well-known URL; otherwise the metadata MUST NOT be used. A mismatch is the classic authorization-server impersonation / mix-up setup.

Remediation

Make issuer exactly equal to the value listed in authorization_servers (same scheme, host, port, path, trailing slash), https, without query or fragment.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31