Skip to content

MCPP-PRM03: PRM resource does not match the server URL

Family Protected Resource Metadata (RFC 9728)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

RFC 9728 §3.3: resource MUST be identical (code point for code point) to the URL the client used, or the metadata MUST NOT be used. The same value is the RFC 8707 audience of issued tokens; a mismatch breaks clients or yields tokens with the wrong audience.

Remediation

Set resource to the exact public URL of the MCP endpoint (scheme, host, port, path; same trailing slash convention), and use it as the token audience.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31