H6.03

OTP and Passwordless Login

Cards in this group · 7

  1. H6.03.1OTP fields must accept paste and autofill
  2. H6.03.2OTP expiry and resend interval must be visible
  3. H6.03.3SMS failure needs a fallback channel
  4. H6.03.4A magic link must expire after one use so forwarding cannot reuse it
  5. H6.03.5Limit OTP guesses to stop brute-force enumeration
  6. H6.03.6Magic links and OTP codes are not equivalent authenticators
  7. H6.03.7Passwordless login still needs a device-side confirmation against intercepted links