OWASP API Security Top 10 - 2023 OWASPAPI-2: Broken Authentication and Token Management
Address API2:2023 Broken Authentication + token management per OWASP API Security Top 10 2023. Broken Authentication occurs when authentication mechanisms are weak + improperly implemented + or bypassable. Mitigations include (a) implement strong authentication (OAuth 2.0 + OIDC + FAPI 2.0 where applicable) + (b) require multi-factor authentication for sensitive operations + privileged accounts + (c) implement rate limiting + account lockout against brute force + credential stuffing, (d) use short-lived access tokens + refresh token rotation + sender-constrained tokens (DPoP + mTLS), (e) protect against session fixation + replay + token theft + (f) maintain secure token storage on client + server, (g) implement proper session termination + logout including all-device logout. Secret and Token Management for APIs (OWASP-API-PRG-04) must (a) maintain secrets in dedicated secret store + (b) rotate regularly + (c) avoid hard-coded secrets + (d) audit secret access.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 56 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.