Skip to content

MCPP-PRM11: PRM variants disagree

Family Protected Resource Metadata (RFC 9728)
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

Clients pick the PRM from the challenge or from different well-known URLs. If those documents name different authorization servers, clients end up in different trust domains (and a stale copy may point to a decommissioned issuer).

Remediation

Serve a single PRM and make every variant (challenge URL, path-inserted, root) return the same authorization servers.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM11"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31