Skip to content

MCPP-CIMD02: Client registration strategies

Family Client ID Metadata Documents
Default severity info
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

MCP clients try pre-registration, then CIMD, then DCR. Knowing which paths an authorization server offers explains how (and whether) arbitrary MCP clients can connect.

Remediation

Informational. Prefer CIMD; keep DCR only for backwards compatibility.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31