← Back to Baseline

MB-R241

HUMAN VERIFICATION REQUIRED ASVS 9.2.4 Audience restriction across services (when self_contained_tokens is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If a token issuer uses the same private key for issuing tokens to different audiences, the issued tokens contain an audience restriction that uniquely identifies the intended audiences. This will prevent a token from being reused with an unintended audience. If the audience identifier is dynamically provisioned, the token issuer must validate these audiences in order to make sure that they do not result in audience impersonation.