
Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC7636
Discuss this RFC: Send questions or comments to the mailing listoauth@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 7636
OAuth 2.0 public clients utilizing the Authorization Code Grant aresusceptible to the authorization code interception attack. Thisspecification describes the attack as well as a technique to mitigateagainst the threat through the use of Proof Key for Code Exchange(PKCE, pronounced "pixy").
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.