Skip to main content
IAMRoadmapIAMRoadmap

PKCE Generator

Generate PKCE code verifier and challenge for OAuth 2.0

Configuration

64

RFC 7636 requires 43-128 characters

Code Verifier

Store securely and send with token request

Click "Generate PKCE Pair" to create a code verifier

Code Challenge

Send with authorization request

Click "Generate PKCE Pair" to create a code challenge

Learn More

About PKCE (RFC 7636)

  • •Proof Key for Code Exchange prevents authorization code interception attacks
  • •S256 method: BASE64URL(SHA256(code_verifier))
  • •Plain method: code_challenge equals code_verifier (less secure)
  • •Required for public clients that cannot securely store secrets

PKCE in IAM

  • •Mobile Apps – Cannot securely store client secrets
  • •Single Page Apps – JavaScript source is publicly accessible
  • •Native Apps – Binaries can be reverse-engineered
  • •OAuth 2.1 – PKCE is required for all clients by default