MCPP-ASM02: Issuer mismatch¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
The issuer in the metadata MUST be identical to the issuer used to build the well-known URL; otherwise the metadata MUST NOT be used. A mismatch is the classic authorization-server impersonation / mix-up setup.
Remediation¶
Make issuer exactly equal to the value listed in authorization_servers (same scheme, host, port, path, trailing slash), https, without query or fragment.
References¶
- RFC 8414 ยง3.3 Metadata Validation
- OpenID Connect Discovery 1.0
- MCP 2026-07-28 Authorization Server Discovery
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31