OAuth discovery metadata points your agent at an internal URL. How would you prevent SSRF?

Instruction: Explain which fetches are at risk, how to enforce destination policy, and how to test redirects and DNS changes.

Context: Secure unfamiliar OAuth metadata URLs fetched by MCP clients and authorization servers without breaking reviewed enterprise integrations.

Updated

Prepare a stronger answer

I’d treat every discovered URL as untrusted input to a privileged network client. That includes resource metadata, authorization-server metadata, and any endpoints taken from those documents. A URL using HTTPS can still target an internal service, so I’d enforce both an allowed scheme and a destination policy...

This member answer includes:

  • • A complete, copyable sample answer
  • • A practical walkthrough
  • • Common mistakes and how to avoid them
  • • Guidance for adapting the answer to your experience
  • • Answered interviewer follow-ups
Unlock the full answer and preparation guide

One payment for one year of full access. No automatic renewal.

See pricing and everything included

Your preparation path

Work through these questions in order. Read the answer aloud, then explain it in your own words.

Related Questions