What this does
PKCE (Proof Key for Code Exchange, RFC 7636) protects the authorization code flow from code interception. The client invents a random secret, the code_verifier, sends only a hash of it, the code_challenge, with the authorization request, and reveals the verifier later when it redeems the code. This page generates the pair.
Rules it follows
- The verifier is 43 to 128 characters from the unreserved set
A-Z a-z 0-9 - . _ ~. - It is generated from your browser's cryptographically secure random source, with rejection sampling so every character is equally likely.
- With S256, the challenge is the base64url encoding (no padding) of the SHA-256 hash of the verifier's ASCII bytes.
- The
plainmethod copies the verifier into the challenge. It is allowed only for clients that cannot compute SHA-256, and it defeats the point of PKCE if an attacker can see the request. Use S256.
Example
The RFC's own test vector works here: paste the verifierdBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk and the S256 challenge comes out as E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM.
Privacy
Verifiers are created and hashed in your browser and are never sent or stored. Generate a new one for every authorization request and never reuse it.