PKCE Generator
Generate PKCE code verifier and challenge for OAuth 2.0
Configuration
64
RFC 7636 requires 43-128 characters
Code Verifier
Store securely and send with token request
Click "Generate PKCE Pair" to create a code verifier
Code Challenge
Send with authorization request
Click "Generate PKCE Pair" to create a code challenge
Learn More
About PKCE (RFC 7636)
- •Proof Key for Code Exchange prevents authorization code interception attacks
- •S256 method:
BASE64URL(SHA256(code_verifier)) - •Plain method: code_challenge equals code_verifier (less secure)
- •Required for public clients that cannot securely store secrets
PKCE in IAM
- •Mobile Apps – Cannot securely store client secrets
- •Single Page Apps – JavaScript source is publicly accessible
- •Native Apps – Binaries can be reverse-engineered
- •OAuth 2.1 – PKCE is required for all clients by default