WTF is PKCE and Why Should You Care?by@janakda
322 reads

WTF is PKCE and Why Should You Care?

tldt arrow
Read on Terminal Reader
Read this story w/o Javascript

Too Long; Didn't Read

PKCE is a mechanism to make the use of OAuth 2.0 Authorization Code grant more secure in certain cases. PKCE prevents an “Authorization Code Interception Attack” The “code verifier” is a random code which meets a certain requirement. The code verifier and the code challenge is created by the client app. Each pair is used only once and cannot be intercepted by an attacker. The Code Verifier and Code Challenge method are optional and the ‘code challenge method’ is optional and it’s used to state the method used.

Coin Mentioned

Mention Thumbnail
featured image - WTF is PKCE and Why Should You Care?
Janak Amarasena HackerNoon profile picture

@janakda

Janak Amarasena


Receive Stories from @janakda

react to story with heart

RELATED STORIES

L O A D I N G
. . . comments & more!
Hackernoon hq - po box 2206, edwards, colorado 81632, usa