MCPP-CIMD55: Private key material in the document¶
| Family | Client ID Metadata Documents |
| Default severity | critical |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
Only public keys may be published. JWK members d, p, q, dp, dq, qi, oth (RSA/EC private parts) or k (symmetric) expose the key that authenticates the client.
Remediation¶
Publish only public JWKs; rotate the exposed key immediately.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD55"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31