Skip to content

MCPP-ASM11: Authorization response iss parameter not supported

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

RFC 9207 iss in authorization responses is the standard defence against mix-up attacks (RFC 9700 ยง2.1). 2026-07-28 makes it a SHOULD; it matters most when a resource lists several authorization servers.

Remediation

Return iss in authorization responses and advertise authorization_response_iss_parameter_supported: true.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM11"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31