Skip to content

MCPP-ASM08: Resource indicator (RFC 8707) enforcement not verified

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity info
Confidence low
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

Audience-restricted tokens are what stops a token minted for one MCP server being replayed against another. No metadata field advertises RFC 8707 support, so a passive scan cannot confirm it.

Remediation

Ensure the authorization server honors resource and sets aud, and that the MCP server rejects tokens for other audiences. Verify it in a test environment: request a token for another resource and confirm the MCP server answers 401.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM08"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31