Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

Is this Sample Project Security Wise Production ready ?

Open
#28 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Bicep
Stars
129
Forks
79
PR merge metrics
No merged PRs in 30d

Description

Hello,

from a security standpoint, is the sample project using API Management as an authorization server (with dynamic client registration and secure remote MCP tools access) production-ready? Specifically, has been properly assessed and evaluated the approach where a dynamically registered MCP client gets a client_id, but the authorization code flow toward Entra uses a different client_id stored in APIM? Does this design introduce security or compliance risks ?

Many thanks for your answer.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.