MCPP-CIMD50: Invalid client identifier URL¶
| Family | Client ID Metadata Documents |
| Default severity | high |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
The client_id of a CIMD client is a URL that authorization servers fetch and compare by simple string equality. It MUST be https with a path and MUST NOT contain userinfo, a fragment or dot segments; anything else is rejected or, worse, accepted inconsistently across servers.
Remediation¶
Host the document at a stable https URL with a dedicated path, e.g. https://app.example.com/oauth/client-metadata.json, without query or fragment.
References¶
- OAuth Client ID Metadata Document (draft-ietf-oauth-client-id-metadata-document-02)
- MCP 2026-07-28 Client Registration
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD50"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31