MCPP-PRM01: Protected Resource Metadata not found¶
| Family | Protected Resource Metadata (RFC 9728) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
Since 2025-06-18, MCP servers that require authorization MUST implement RFC 9728 so clients can discover the authorization server. Without PRM, compliant clients cannot start the OAuth flow.
Remediation¶
Serve a JSON document at /.well-known/oauth-protected-resource<path> containing at least resource (the exact MCP URL) and authorization_servers.
References¶
- RFC 9728 Protected Resource Metadata
- MCP 2025-06-18 Authorization
- MCP 2026-07-28 Authorization Server Discovery
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31