Skip to content

MCPP-PRM05: Authorization server issuer not HTTPS

Family Protected Resource Metadata (RFC 9728)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

Issuer identifiers MUST use https (RFC 8414 ยง2) and all authorization server endpoints MUST be served over HTTPS (MCP authorization, communication security).

Remediation

List only https:// issuers in authorization_servers.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31