OtherActive

OAuth 2.0 PKCE

RFC 7636 extension preventing authorization code injection and CSRF attacks in OAuth 2.0 Authorization Code flow.

Open source page

Field note

What it does

Proof Key for Code Exchange (PKCE) generates a random code verifier and derives a code challenge for the authorization request, ensuring only the initiating client can complete the flow.

Capabilities

Available capabilities

Tags

Tags

Ways to use it

Ways to use it

No integrations filed yet.

Product features

Product features

Additional Extensions

Code and Services

Community Resources

Discovery and Registration

Draft Specs

High Security OAuth

Mobile and Other Devices

OAuth 2.0

OAuth 2.1

Protocols Built on OAuth 2.0

Related Work from Other Communities

Token and Token Management