MCPP-CIMD57: Document not served the way authorization servers fetch it¶
| Family | Client ID Metadata Documents |
| Default severity | medium |
| Confidence | high |
| Mode | mcp-posture cimd lint only |
| Spec revisions | 2025-11-25 and later |
Why it matters¶
Authorization servers MUST treat any status other than 200 as an error, MUST NOT follow redirects, SHOULD cap the size (about 5 KB) and expect JSON. A document that only works through a redirect or is too large fails in production.
Remediation¶
Serve the document directly (200, no redirect) as application/json, under 5 KB, with sensible Cache-Control.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-CIMD57"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31