PKCE (Proof Key for Code Exchange)
An OAuth 2.0 extension (RFC 7636) that binds an authorization code to the client that requested it, designed so that an intercepted code cannot be redeemed by another party.
Proof Key for Code Exchange, pronounced “pixy”, is an extension to the OAuth 2.0 authorization code grant, defined in RFC 7636. It was written for public clients, such as mobile and single-page applications that cannot keep a client secret, where an intercepted authorization code could otherwise be redeemed by an attacker. Before the flow starts, the client creates a random secret, the code verifier, and sends a code challenge derived from it with the authorization request, commonly its SHA-256 hash. When it later exchanges the code for tokens, it presents the verifier itself, and the authorization server checks it against the challenge.
RFC 7636 permits a plain method, where the challenge equals the verifier, only for clients that cannot use SHA-256. RFC 9700 (January 2025), the OAuth 2.0 security best current practice, requires PKCE for public clients and recommends it for confidential ones. PKCE does not authenticate the user, which is the job of OpenID Connect layered on OAuth, and it does not protect an access token once issued.
Exam relevance: a scenario is likely to describe a mobile or browser application using the authorization code flow and ask how to stop a stolen code being redeemed. Candidates are expected to choose PKCE and to keep it apart from a client secret, which a public OAuth client cannot protect.