← Back to Baseline

MB-R242

HUMAN VERIFICATION REQUIRED ASVS 10.1.1 Token minimization (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

Tokens are only sent to components that strictly need them. For example, when using a backend-for-frontend pattern for browser-based JavaScript applications, access and refresh tokens shall only be accessible for the backend.