MCPP-ASM12: Unsigned (alg=none) client authentication allowed¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
RFC 8414 ยง2: the value none MUST NOT be used in the signing algorithm lists for endpoint authentication; it would accept unsigned client assertions.
Remediation¶
Remove none from the *_auth_signing_alg_values_supported lists.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM12"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31