MCPP-CIMD53: Unsafe redirect URI¶
| Family | Client ID Metadata Documents |
| Default severity | medium |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
Authorization codes are delivered to the redirect URI. Plain-http non-loopback, wildcard, fragment or script URIs leak codes; loopback-only documents can be impersonated by any local app, which is why MCP asks authorization servers to warn on them.
Remediation¶
Use https redirect URIs (or loopback for native apps with PKCE), with exact values, no wildcards and no fragments.
References¶
- OAuth Client ID Metadata Document (draft-ietf-oauth-client-id-metadata-document-02)
- OAuth 2.1 (draft-ietf-oauth-v2-1-16)
- RFC 9700 OAuth 2.0 Security BCP
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD53"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31