Proof Key for Code Exchange (PKCE)
Proof Key for Code Exchange (PKCE) is an OAuth 2.0 extension designed to enhance security during authorization code flows, particularly for public clients like mobile or single-page applications. It mitigates the risk of authorization code interception by requiring a dynamically generated code verifier and its hashed code challenge to be exchanged between the client and authorization server, ensuring only the legitimate client can obtain the access token.
Wherever possible the Client SDK's Authorization Code Flow authentication flow will automatically generate and include a PKCE object when a user begins authenticating. Since PKCE involves multiple steps, and contains state that needs to be persisted between when the flow is started and when it is completed, this data should be encapsulated within the authentication flow's Context instance.