Skip to content

MCPP-ASM12: Unsigned (alg=none) client authentication allowed

Family Authorization Server Metadata (RFC 8414 / OIDC)
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

RFC 8414 ยง2: the value none MUST NOT be used in the signing algorithm lists for endpoint authentication; it would accept unsigned client assertions.

Remediation

Remove none from the *_auth_signing_alg_values_supported lists.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM12"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31