Skip to content

MCPP-PRM04: PRM lists no authorization server

Family Protected Resource Metadata (RFC 9728)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

The MCP spec requires PRM to include authorization_servers with at least one issuer; otherwise clients have nowhere to obtain a token.

Remediation

Add "authorization_servers": ["https://<issuer>"].

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM04"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31