MCPP-CIMD56: Authentication method inconsistent with key material¶
| Family | Client ID Metadata Documents |
| Default severity | medium |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
private_key_jwt needs public keys (jwks or jwks_uri) for the authorization server to verify assertions; RFC 7591 forbids sending both jwks and jwks_uri; keys published by a public client are unused and confusing.
Remediation¶
For private_key_jwt, publish exactly one of jwks or jwks_uri (https). For a public client, use none and drop the keys.
References¶
- OAuth Client ID Metadata Document (draft-ietf-oauth-client-id-metadata-document-02)
- RFC 7591 Dynamic Client Registration
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD56"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31