MCPP-ASM05: PKCE plain method allowed¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
The plain transformation sends the verifier in the authorization request, which defeats PKCE against an attacker who can read it, and allows downgrade. OAuth 2.1 prohibits it.
Remediation¶
Advertise and accept only S256.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31