MCPP-ASM06: Deprecated grant types enabled¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
OAuth 2.1 removes the implicit and resource owner password grants; RFC 9700 says the password grant MUST NOT be used. When grant_types_supported is omitted, RFC 8414 defaults it to authorization_code and implicit.
Remediation¶
Disable implicit and password grants and list the supported grants explicitly, e.g. ["authorization_code", "refresh_token"].
References¶
- OAuth 2.1 (draft-ietf-oauth-v2-1-16)
- RFC 9700 OAuth 2.0 Security BCP
- RFC 8414 Authorization Server Metadata
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM06"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31