createmcps.com

MCP-AUT-008

Tokens with a foreign audience are rejected

MCP servers MUST validate that access tokens were issued specifically for them as the intended audience, according to RFC 8707 Section 2.spec anchor

How to fix this

Requires a token minted for a different audience — needs a private authenticated run; v2.

How the validator checks this

Probe P8.1, against a streamable-http server on the modern protocol. What it reports:

skip
No authorization, so token audience validation does not apply

Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.

This rule is checked heuristically: a fail is inferred rather than certain, so it bumps the overall grade up one level instead of being treated as certain non-compliance.

Checked in the same request as MCP-AUT-001, MCP-AUT-006, MCP-AUT-007, MCP-SEC-007.

Check your own server against this rule

The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.

Other Authorization rules

  • MCP-AUT-001Unauthenticated request returns 401 with WWW-Authenticate resource_metadata
  • MCP-AUT-002RFC 9728 Protected Resource Metadata is served and valid
  • MCP-AUT-003PRM resource equals the canonical server URI
  • MCP-AUT-004Each listed authorization server exposes RFC 8414 or OIDC discovery metadata
  • MCP-AUT-005AS advertises authorization_response_iss_parameter_supported: true
  • MCP-AUT-006WWW-Authenticate includes a scope parameter
  • MCP-AUT-007Insufficient scope returns 403 with error="insufficient_scope"
  • MCP-AUT-009offline_access absent from scopes_supported / challenge scope
  • MCP-AUT-010AS advertises S256 in code_challenge_methods_supported
  • MCP-AUT-011AS supports Client ID Metadata Documents, not DCR alone