>_devtools

PKCE Code Verifier & Challenge Generator

Generate a PKCE code_verifier of 43 to 128 characters and its S256 code_challenge for OAuth 2.0 and OpenID Connect, using your browser's secure random source.

What this does

PKCE (Proof Key for Code Exchange, RFC 7636) protects the authorization code flow from code interception. The client invents a random secret, the code_verifier, sends only a hash of it, the code_challenge, with the authorization request, and reveals the verifier later when it redeems the code. This page generates the pair.

Rules it follows

  • The verifier is 43 to 128 characters from the unreserved set A-Z a-z 0-9 - . _ ~.
  • It is generated from your browser's cryptographically secure random source, with rejection sampling so every character is equally likely.
  • With S256, the challenge is the base64url encoding (no padding) of the SHA-256 hash of the verifier's ASCII bytes.
  • The plain method copies the verifier into the challenge. It is allowed only for clients that cannot compute SHA-256, and it defeats the point of PKCE if an attacker can see the request. Use S256.

Example

The RFC's own test vector works here: paste the verifierdBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk and the S256 challenge comes out as E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM.

Privacy

Verifiers are created and hashed in your browser and are never sent or stored. Generate a new one for every authorization request and never reuse it.