MCPP-TRN01: MCP endpoint not served over HTTPS¶
| Family | Transport |
| Default severity | critical |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Bearer tokens, tool arguments and results travel in clear text over plain HTTP. The MCP authorization spec requires HTTPS for all authorization-related traffic, and bearer tokens must only be sent over TLS.
Remediation¶
Serve the MCP endpoint over HTTPS only (TLS 1.2+), and redirect or refuse plain HTTP. Loopback development servers are exempt.
References¶
- MCP 2025-11-25 Authorization
- RFC 9325 (BCP 195) TLS Recommendations
- OAuth 2.1 (draft-ietf-oauth-v2-1-16)
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31