MCPP-ASM11: Authorization response iss parameter not supported¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
RFC 9207 iss in authorization responses is the standard defence against mix-up attacks (RFC 9700 ยง2.1). 2026-07-28 makes it a SHOULD; it matters most when a resource lists several authorization servers.
Remediation¶
Return iss in authorization responses and advertise authorization_response_iss_parameter_supported: true.
References¶
- RFC 9207 Issuer Identification
- RFC 9700 OAuth 2.0 Security BCP
- MCP 2026-07-28 Authorization Security Considerations
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM11"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31