← Back to Baseline

MB-R249

HUMAN VERIFICATION REQUIRED ASVS 10.3.4 Authentication strength and freshness (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If the resource server requires specific authentication strength, methods, or recentness, it verifies that the presented access token satisfies these constraints. For example, if present, using the OIDC 'acr', 'amr'and 'auth\_time'claims respectively.