MCPP-TRN11: MCP endpoint redirects¶
| Family | Transport |
| Default severity | info |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
The URL users configure is the resource identifier: clients compare it with PRM resource and send it as the RFC 8707 resource parameter. When the endpoint redirects (often a framework adding a trailing slash), some clients do not follow redirects on POST, and a redirect to another origin drops the bearer token. The scanner follows same-origin 307/308 redirects like a client would, and never follows across origins.
Remediation¶
Serve the MCP endpoint at the URL you publish without a redirect (or publish the final URL), and keep PRM resource equal to that URL.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN11"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31