← Back to Baseline

MB-R190

HUMAN VERIFICATION REQUIRED ASVS 13.2.1 Backend authentication

MB-C15 ASVS Level 2 Human Assurance Medium

Communications between backend application components that don't support the application's standard user session mechanism, including APIs, middleware, and data layers, are authenticated. Authentication must use individual service accounts, short-term tokens, or certificate-based authentication and not unchanging credentials such as passwords, API keys, or shared accounts with privileged access.