OAuth 2.0 Authorization Code Flow with PKCE
Classic three-party flow where a client application exchanges an authorization code for an access token and binds the exchange to a PKCE code verifier.
The Authorization Code with PKCE flow is the recommended flow for applications that can't keep a client secret (public clients). The user authenticates with the authorization server, which then issues a short-lived code bound to a one-time code_verifier. When the application exchanges the code for tokens, the code_verifier proves that the same client that started the flow is now redeeming the code.
While this flow was intended for public clients, OAuth 2.1 recommends it even for confidential clients. In this case, the client_secret is mandatory to exchange the code for a token.