reap / rules / auth and session posture
Published OAuth metadata does not advertise PKCE
mcp-oauth-metadata-posture ASI03 Identity and Privilege Abuse severity: low
What it detects
Published OAuth metadata not advertising PKCE (code_challenge_methods_supported). ASI03.
Checks published OAuth authorization-server/protected-resource metadata (.well-known/*) for PKCE advertisement (code_challenge_methods_supported).
applies to MCP endpoints
Why it matters
MCP clients are public OAuth clients, for which PKCE is required. Without it, an intercepted authorization code is redeemable — an identity weakness.
Example finding
LOW mcp-oauth-metadata-posture HIGH CONFIDENCE Published OAuth metadata does not advertise PKCE OAuth metadata was published at /.well-known/oauth-authorization-server, but it does not advertise PKCE (code_challenge_methods_supported) support. Evidence GET /.well-known/oauth-authorization-server → 200
from a scan of reap-range, bad target
Fix
Advertise PKCE support (code_challenge_methods_supported: ["S256"]) in published OAuth authorization-server metadata.
On reap-range
| insecure target | bad host well-known (no code_challenge_methods_supported) · Low |
| correct target | good host well-known advertises ["S256"] |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-oauth-metadata-posture
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.