Skip to content

MCPP-CIMD01: Client ID Metadata Documents not advertised

Family Client ID Metadata Documents
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions 2025-11-25 and later

Why it matters

Since 2025-11-25 authorization servers SHOULD support CIMD, and CIMD-capable servers MUST say so with client_id_metadata_document_supported. Without it, MCP clients fall back to DCR or manual pre-registration.

Remediation

Implement CIMD (fetch the client_id URL, validate per the draft's §4-§8) and advertise client_id_metadata_document_supported: true.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31