MCPP-ASM04: PKCE S256 not advertised¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | critical |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
PKCE is mandatory for MCP clients, and since 2025-11-25 clients MUST refuse to proceed when code_challenge_methods_supported is absent. Without S256, authorization codes can be intercepted and redeemed by an attacker.
Remediation¶
Enforce PKCE and advertise "code_challenge_methods_supported": ["S256"].
References¶
- RFC 7636 PKCE
- OAuth 2.1 (draft-ietf-oauth-v2-1-16)
- RFC 9700 OAuth 2.0 Security BCP
- MCP 2025-11-25 Authorization
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM04"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31