OWASP ASVS V2NIST SP 800-63B
Authentication & Password Policy
Detailed controls for identity verification, OAuth flows, session lifecycle, password reset tokens, and MFA enforcement.
Audit Progress: 0 of 2 verified
Check off items as you verify them in your codebase. Progress is saved locally.
Showing 2 checks
Password PolicyHigh
Password reset tokens expire and are single-use
Ensure password recovery tokens are securely hashed in the database, expire in under 15–30 minutes, and are immediately invalidated upon use.
OAuth / OIDCHigh
OAuth state parameter is validated against CSRF
Protect social logins (GitHub, Google) by generating unpredictable state parameters and verifying them upon callback.