Back to Checklists
OWASP ASVS V2NIST SP 800-63B

Authentication & Password Policy

Detailed controls for identity verification, OAuth flows, session lifecycle, password reset tokens, and MFA enforcement.

Support SafeToShip

Audit Progress: 0 of 2 verified

Check off items as you verify them in your codebase. Progress is saved locally.

Showing 2 checks
Password PolicyHigh

Password reset tokens expire and are single-use

Ensure password recovery tokens are securely hashed in the database, expire in under 15–30 minutes, and are immediately invalidated upon use.

OAuth / OIDCHigh

OAuth state parameter is validated against CSRF

Protect social logins (GitHub, Google) by generating unpredictable state parameters and verifying them upon callback.