Skip to content

MCPP-ASM05: PKCE plain method allowed

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

The plain transformation sends the verifier in the authorization request, which defeats PKCE against an attacker who can read it, and allows downgrade. OAuth 2.1 prohibits it.

Remediation

Advertise and accept only S256.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31