MCPP-PRM03: PRM resource does not match the server URL¶
| Family | Protected Resource Metadata (RFC 9728) |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
RFC 9728 §3.3: resource MUST be identical (code point for code point) to the URL the client used, or the metadata MUST NOT be used. The same value is the RFC 8707 audience of issued tokens; a mismatch breaks clients or yields tokens with the wrong audience.
Remediation¶
Set resource to the exact public URL of the MCP endpoint (scheme, host, port, path; same trailing slash convention), and use it as the token audience.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31