Skip to content

MCPP-ASM06: Deprecated grant types enabled

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

OAuth 2.1 removes the implicit and resource owner password grants; RFC 9700 says the password grant MUST NOT be used. When grant_types_supported is omitted, RFC 8414 defaults it to authorization_code and implicit.

Remediation

Disable implicit and password grants and list the supported grants explicitly, e.g. ["authorization_code", "refresh_token"].

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM06"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31