Skip to content

MCPP-TRN01: MCP endpoint not served over HTTPS

Family Transport
Default severity critical
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

Bearer tokens, tool arguments and results travel in clear text over plain HTTP. The MCP authorization spec requires HTTPS for all authorization-related traffic, and bearer tokens must only be sent over TLS.

Remediation

Serve the MCP endpoint over HTTPS only (TLS 1.2+), and redirect or refuse plain HTTP. Loopback development servers are exempt.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31