MCPP-PRM10: offline_access advertised by the resource¶
| Family | Protected Resource Metadata (RFC 9728) |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2026-07-28 |
Why it matters¶
2026-07-28: MCP servers SHOULD NOT include offline_access in scopes_supported or challenges; refresh-token issuance is the client's and authorization server's decision, and advertising it nudges clients into long-lived credentials.
Remediation¶
Remove offline_access from scopes_supported.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31