MCPP-CIMD54: Shared secret in a public metadata document¶
| Family | Client ID Metadata Documents |
| Default severity | critical |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
The document is public. Draft-02 ยง4.1 forbids client_secret, client_secret_expires_at and every shared-secret authentication method: a secret published at a URL is not a secret.
Remediation¶
Remove the secret and rotate it now. Use none (public client with PKCE) or private_key_jwt with public keys in jwks / jwks_uri.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD54"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31