Credential Access
High
- Category
- Privilege Escalation
- Content
## Authentication Maverick performs MCP-native OAuth Authorization Code with PKCE and dynamic public-client registration, then seeds the access token, refresh token, and issued client id into mcporter's vault through `scripts/setup.sh`. mcporter uses OAuth protected-resource discovery when refreshing, which preserves Trello's `https://mcp.trello.com/v1` resource indicator. Setup requires these credential variables:
- Confidence
- 78% confidence
- Finding
- access token
