hackwither_

reap / rules / auth and session posture

Published OAuth metadata does not advertise PKCE

mcp-oauth-metadata-posture ASI03 Identity and Privilege Abuse severity: low

What it detects

Published OAuth metadata not advertising PKCE (code_challenge_methods_supported). ASI03.

Checks published OAuth authorization-server/protected-resource metadata (.well-known/*) for PKCE advertisement (code_challenge_methods_supported).

applies to MCP endpoints

Why it matters

MCP clients are public OAuth clients, for which PKCE is required. Without it, an intercepted authorization code is redeemable — an identity weakness.

OWASP ASI mapping rationale

Example finding

LOW  mcp-oauth-metadata-posture  HIGH CONFIDENCE
Published OAuth metadata does not advertise PKCE
OAuth metadata was published at /.well-known/oauth-authorization-server, but it does not advertise PKCE (code_challenge_methods_supported) support.
Evidence  GET /.well-known/oauth-authorization-server → 200

from a scan of reap-range, bad target

Fix

Advertise PKCE support (code_challenge_methods_supported: ["S256"]) in published OAuth authorization-server metadata.

On reap-range

insecure targetbad host well-known (no code_challenge_methods_supported) · Low
correct targetgood host well-known advertises ["S256"]

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-oauth-metadata-posture

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.