MCPP-AUTHN04: resource_metadata URL not HTTPS or on another origin¶
| Family | Authentication challenge |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
The PRM URL tells clients which authorization server to trust. Over plain HTTP it can be tampered with; on another origin it deserves a look, since the server delegates trust to a third party.
Remediation¶
Serve the PRM over HTTPS, preferably from the MCP server's own origin.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN04"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31