OpenID Connect - Authorization Code Flow with PKCE

Recommended OIDC login flow where the client exchanges an authorization code for tokens and binds the exchange to a PKCE code verifier.

User Login & SSO

In OpenID Connect, Authorization Code with PKCE is the recommended browser-based sign-in pattern for modern clients. The browser only carries the short-lived authorization code, while the token exchange is bound to a one-time code_verifier that proves the same client started the flow and is now redeeming the code.

OpenID ProviderClient AppBrowserUserOpenID ProviderClient AppBrowserUserClick "Login"1GET /login2Generate code verifier and challenge3302 to IdP4GET /authorize5Login6Credentials7Consent prompt8Scope approval9302 to redirect_uri10GET redirect_uri11POST /oauth/token12ID token, Access token13Set authenticated session14Access welcome page15200 OK - Welcome page16

Official Specifications

Additional Resources

Back to all diagrams