HTTP redirect URI (non-HTTPS)
AI security governance · MCP security
Severity
high
What it is
The OAuth redirect URI uses plain HTTP instead of HTTPS, exposing tokens to network interception.
How Igris detects it
Igris's OAuth Configuration Checker flags this during MCP security scans of your configuration.
References
Related MCP security rules
Secure your AI estate with Igris