Session Token
What is Session Token?
A unique identifier issued to a user after successful authentication, used to maintain their authenticated state across subsequent requests.
Terms that appear alongside session token
Each of these is named in at least one of the same controls as session token. The number is how many controls name both.
- authentication 3 shared controls
- mitre 2 shared controls
- enisa 2 shared controls
- passkey 2 shared controls
Frameworks that govern session token
What the standards actually require on session token
Requirements naming session token across 5 standards, quoted from the control text.
WebAuthn authentication ceremony per W3C L3 5.2 (Credential Assertion). FLOW: (1) RP server generates PublicKeyCredentialRequestOptions: challenge + rpId + (optional) allowCredentials + userVerification + hints + extensions + sends to client.
FIDO2-Authentication-Ceremony · WebAuthn Authentication Ceremony (Credential Assertion) →Apply D3FEND DECEIVE tactic to present false data and impressions to adversaries to misdirect their efforts. D3-DE Decoy Environment (D3-DST Decoy Session Token + D3-DPB Decoy Public Release + D3-CDE Connected Honeynet + D3-DUC Decoy User Credential + D3-IDA I...
MITRE-D3FEND-Deceive-Tactic-Decoy-Environment-Decoy-Object-Honeypots-Honey-Tokens-Decoy-Network · MITRE D3FEND Deceive Tactic + Decoy Environment + Decoy Object + Honeypots + Honey Tokens + Decoy Network →Operate cross-cutting controls per NIST SP 800-63-4. Identity service operational audit per Volume B Chapter 10: continuous audit of authentication events + identity proofing decisions + federation assertions + administrative actions with retention aligned to...
NISTSP63R4-8 · Operational Audit, Session Management, Recovery, and Cross-cutting Controls →Per OWASP ASVS V3: implement secure session management. Requirements include (a) generate cryptographically random session tokens of sufficient entropy + (b) protect tokens against session fixation + replay + theft + (c) implement secure cookie attributes (Sec...
OWASPASVS-3 · Session Management (V3) →Per OWASP MASVS v2 MASVS-AUTH: secure authentication and authorization in mobile apps. Requirements include (a) implement strong server-side authentication aligned to standards (OAuth 2.0 + OIDC + FIDO2/WebAuthn + biometric where appropriate) + (b) require mul...
OWASPMASVS-3 · MASVS-AUTH: Authentication and Authorization →Questions people ask about session token
What is Session Token?
Why is Session Token important for compliance?
Which compliance frameworks address Session Token?
Where can I learn more about Session Token?
See how Session Token applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.