Skip to content

MCPP-PRM06: Bearer tokens accepted in the query string

Family Protected Resource Metadata (RFC 9728)
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

Tokens in URLs leak into logs, proxies and Referer headers. OAuth 2.1 and the MCP spec forbid them; RFC 6750 ยง2.3 says the method SHOULD NOT be used.

Remediation

Remove query from bearer_methods_supported and ignore access_token query parameters on the resource server.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM06"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31