Skip to content

MCPP-CIMD50: Invalid client identifier URL

Family Client ID Metadata Documents
Default severity high
Confidence high
Mode mcp-posture cimd lint only
Spec revisions 2025-11-25 and later

Why it matters

The client_id of a CIMD client is a URL that authorization servers fetch and compare by simple string equality. It MUST be https with a path and MUST NOT contain userinfo, a fragment or dot segments; anything else is rejected or, worse, accepted inconsistently across servers.

Remediation

Host the document at a stable https URL with a dedicated path, e.g. https://app.example.com/oauth/client-metadata.json, without query or fragment.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD50"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31