← Back to Baseline

MB-R251

HUMAN VERIFICATION REQUIRED ASVS 10.4.7 Dynamic-client registration safety (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

If the authorization server supports unauthenticated dynamic client registration, it mitigates the risk of malicious client applications. It must validate client metadata such as any registered URIs, ensure the user's consent, and warn the user before processing an authorization request with an untrusted client application.