OpenID Connect - Authorization Code Flow with PKCE
Recommended OIDC login flow where the client exchanges an authorization code for tokens and binds the exchange to a PKCE code verifier.
In OpenID Connect, Authorization Code with PKCE is the recommended browser-based sign-in pattern for modern clients. The browser only carries the short-lived authorization code, while the token exchange is bound to a one-time code_verifier that proves the same client started the flow and is now redeeming the code.