← Back to Baseline

MB-R323

HUMAN VERIFICATION REQUIRED ASVS 10.3.5 Sender-constrained access tokens (when oauth_oidc is used)

MB-C18 ASVS Level 3 Human Assurance High

The resource server prevents the use of stolen access tokens or replay of access tokens (from unauthorized parties) by requiring sender-constrained access tokens, either Mutual TLS for OAuth 2 or OAuth 2 Demonstration of Proof of Possession (DPoP).