Skip to content

Session Token

What is Session Token?

A unique identifier issued to a user after successful authentication, used to maintain their authenticated state across subsequent requests.

Information Security

Each of these is named in at least one of the same controls as session token. The number is how many controls name both.

What the standards actually require on session token

Requirements naming session token across 5 standards, quoted from the control text.

WebAuthn authentication ceremony per W3C L3 5.2 (Credential Assertion). FLOW: (1) RP server generates PublicKeyCredentialRequestOptions: challenge + rpId + (optional) allowCredentials + userVerification + hints + extensions + sends to client.

FIDO2-Authentication-Ceremony · WebAuthn Authentication Ceremony (Credential Assertion)
MITRE D3FEND2 controls

Apply D3FEND DECEIVE tactic to present false data and impressions to adversaries to misdirect their efforts. D3-DE Decoy Environment (D3-DST Decoy Session Token + D3-DPB Decoy Public Release + D3-CDE Connected Honeynet + D3-DUC Decoy User Credential + D3-IDA I...

MITRE-D3FEND-Deceive-Tactic-Decoy-Environment-Decoy-Object-Honeypots-Honey-Tokens-Decoy-Network · MITRE D3FEND Deceive Tactic + Decoy Environment + Decoy Object + Honeypots + Honey Tokens + Decoy Network

Operate cross-cutting controls per NIST SP 800-63-4. Identity service operational audit per Volume B Chapter 10: continuous audit of authentication events + identity proofing decisions + federation assertions + administrative actions with retention aligned to...

NISTSP63R4-8 · Operational Audit, Session Management, Recovery, and Cross-cutting Controls
OWASP ASVS1 control

Per OWASP ASVS V3: implement secure session management. Requirements include (a) generate cryptographically random session tokens of sufficient entropy + (b) protect tokens against session fixation + replay + theft + (c) implement secure cookie attributes (Sec...

OWASPASVS-3 · Session Management (V3)
OWASP MASVS1 control

Per OWASP MASVS v2 MASVS-AUTH: secure authentication and authorization in mobile apps. Requirements include (a) implement strong server-side authentication aligned to standards (OAuth 2.0 + OIDC + FIDO2/WebAuthn + biometric where appropriate) + (b) require mul...

OWASPMASVS-3 · MASVS-AUTH: Authentication and Authorization

Questions people ask about session token

What is Session Token?
A unique identifier issued to a user after successful authentication, used to maintain their authenticated state across subsequent requests.
Why is Session Token important for compliance?
Session Token is a key concept in Information Security. Understanding session token helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Session Token?
Session Token appears in the requirement text of FIDO2 / WebAuthn, MITRE D3FEND, NIST SP 800-63-4, OWASP ASVS, OWASP MASVS. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Session Token?
Explore our compliance framework pages to see how session token applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Session Token applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.