MCPP-ASM10: Dynamic Client Registration without Client ID Metadata Documents¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
Since 2025-11-25, CIMD is the recommended registration path (SHOULD) and DCR is optional; 2026-07-28 deprecates DCR. An AS offering only DCR keeps the open registration surface and gives clients no verifiable identity.
Remediation¶
Enable Client ID Metadata Document support and advertise client_id_metadata_document_supported: true.
References¶
- MCP 2025-11-25 Authorization
- MCP 2026-07-28 Client Registration
- OAuth Client ID Metadata Document (draft-ietf-oauth-client-id-metadata-document-02)
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31