7 Matching Annotations
- Nov 2022
-
www.jvt.me www.jvt.me
-
-
Proof of Key Code Exchange is an OAuth2 extension that recently been adopted as the standard for both OAuth 2.1 and IndieAuth, and provides additional security for attacks on the Authorization Code flow.
-
-
developer.okta.com developer.okta.com
-
Here’s what this flow looks like:
-
-
-
the OAuth 2.0 grant type, Authorization Code Flow with Proof Key for Code Exchange (PKCE).
-
- Sep 2019
-
remotesynthesis.com remotesynthesis.com
-
it's not that there are new vulnerabilities that have been identified in the implicit flow, just that PKCE offers a more secure alternative that you should use if you have the option
Use PKCE instead of the implicit flow if you have a chance
-
PKCE (which stands for "Proof Key for Code Exchange" and is pronounced "pixie") was originally developed to solve a problem specific to native mobile apps using OAuth 2.0
PKCE (Proof Key for Code Exchange) is an extension to OAuth 2.0
Tags
Annotators
URL
-