MCPP-CIMD51: Document client_id does not match its URL¶
| Family | Client ID Metadata Documents |
| Default severity | high |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
Authorization servers MUST reject a document whose client_id is not exactly the URL it was fetched from (simple string comparison: no normalization of case, default ports or trailing slashes).
Remediation¶
Set client_id to the exact URL the document is served at.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD51"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31