Skip to content

MCPP-ASM03: Authorization server endpoint not HTTPS

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

All authorization server endpoints MUST be served over HTTPS (MCP authorization, communication security). Codes, tokens and client credentials would otherwise travel in clear text.

Remediation

Publish only https:// endpoint URLs.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31