MCPP-ASM07: Response types incompatible with OAuth 2.1¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
MCP uses the authorization code flow, so code must be supported; response types returning an access token from the authorization endpoint (token) are the implicit flow, removed in OAuth 2.1.
Remediation¶
Support code; remove response types containing token.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM07"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31