Proof Key for Code Exchange by OAuth Public Clients
Author(s) -
John Bradley,
Neeraj Agarwal
Publication year - 2015
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc7636
Subject(s) - authorization , code (set theory) , key (lock) , computer security , computer science , business , internet privacy , programming language , set (abstract data type)
OAuth 2.0 public clients utilizing the Authorization Code Grant aresusceptible to the authorization code interception attack. Thisspecification describes the attack as well as a technique to mitigateagainst the threat through the use of Proof Key for Code Exchange(PKCE, pronounced "pixy").
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom