Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python
Is this Sample Project Security Wise Production ready ?
Offen
- Vorherrschende Sprache
- Bicep
- Sterne
- 129
- Forks
- 79
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
Hello,
from a security standpoint, is the sample project using API Management as an authorization server (with dynamic client registration and secure remote MCP tools access) production-ready? Specifically, has been properly assessed and evaluated the approach where a dynamically registered MCP client gets a client_id, but the authorization code flow toward Entra uses a different client_id stored in APIM? Does this design introduce security or compliance risks ?
Many thanks for your answer.
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.