MCPP-ASM03: Authorization server endpoint not HTTPS¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
All authorization server endpoints MUST be served over HTTPS (MCP authorization, communication security). Codes, tokens and client credentials would otherwise travel in clear text.
Remediation¶
Publish only https:// endpoint URLs.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31