← Back to Baseline

MB-R256

HUMAN VERIFICATION REQUIRED ASVS 10.5.1 ID Token replay defense (when oauth_oidc is used)

MB-C16 ASVS Level 2 Contextual Human Assurance High

The client (as the relying party) mitigates ID Token replay attacks. For example, by ensuring that the 'nonce'claim in the ID Token matches the 'nonce'value sent in the authentication request to the OpenID Provider (in OAuth2 refereed to as the authorization request sent to the authorization server).