Skip to content

MCPP-AUTHN04: resource_metadata URL not HTTPS or on another origin

Family Authentication challenge
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

The PRM URL tells clients which authorization server to trust. Over plain HTTP it can be tampered with; on another origin it deserves a look, since the server delegates trust to a third party.

Remediation

Serve the PRM over HTTPS, preferably from the MCP server's own origin.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-AUTHN04"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31