MCPP-ASM13: Default authorization endpoints without metadata (2025-03-26)¶
| Family | Authorization Server Metadata (RFC 8414 / OIDC) |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-03-26 |
Why it matters¶
In 2025-03-26 the MCP server is its own authorization server; without RFC 8414 metadata, clients guess /authorize, /token and /register and cannot verify PKCE support or endpoint policy.
Remediation¶
Publish /.well-known/oauth-authorization-server at the server origin, or move to the 2025-06-18+ model with a separate authorization server and PRM.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-ASM13"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31