Skip to content

MCPP-CIMD51: Document client_id does not match its URL

Family Client ID Metadata Documents
Default severity high
Confidence high
Mode mcp-posture cimd lint only
Spec revisions 2025-11-25 and later

Why it matters

Authorization servers MUST reject a document whose client_id is not exactly the URL it was fetched from (simple string comparison: no normalization of case, default ports or trailing slashes).

Remediation

Set client_id to the exact URL the document is served at.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD51"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31