Skip to content

MCPP-PRM10: offline_access advertised by the resource

Family Protected Resource Metadata (RFC 9728)
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions 2026-07-28

Why it matters

2026-07-28: MCP servers SHOULD NOT include offline_access in scopes_supported or challenges; refresh-token issuance is the client's and authorization server's decision, and advertising it nudges clients into long-lived credentials.

Remediation

Remove offline_access from scopes_supported.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31