H6.03
OTP and Passwordless Login
Cards in this group · 7
- H6.03.1OTP fields must accept paste and autofill
- H6.03.2OTP expiry and resend interval must be visible
- H6.03.3SMS failure needs a fallback channel
- H6.03.4A magic link must expire after one use so forwarding cannot reuse it
- H6.03.5Limit OTP guesses to stop brute-force enumeration
- H6.03.6Magic links and OTP codes are not equivalent authenticators
- H6.03.7Passwordless login still needs a device-side confirmation against intercepted links