OAuth 2.0 Authorization Code Flow with PKCE

Classic three-party flow where a client application exchanges an authorization code for an access token and binds the exchange to a PKCE code verifier.

Application & API Security

The Authorization Code with PKCE flow is the recommended flow for applications that can't keep a client secret (public clients). The user authenticates with the authorization server, which then issues a short-lived code bound to a one-time code_verifier. When the application exchanges the code for tokens, the code_verifier proves that the same client that started the flow is now redeeming the code.

While this flow was intended for public clients, OAuth 2.1 recommends it even for confidential clients. In this case, the client_secret is mandatory to exchange the code for a token.

OPResource ServerAuthorization ServerClient AppBrowserUserOPResource ServerAuthorization ServerClient AppBrowserUserOpen protected page1GET /page2GET api/resource3401 Unauthorized4Generate code_verifier + code_challenge5302 to /authorize6GET /authorize7Login8Credentials9Consent prompt10Scope approval11302 to redirect_uri12GET redirect_uri13POST /oauth/token14Access_token15GET /api/resource16200 OK - Resource payload17Rendered page18

Official Specifications

Additional Resources

Back to all diagrams