Suggested answer

PKCE (Proof Key for Code Exchange) is used when a public app (a client that cannot securely store a client_secret — e.g., a single-page app or mobile app) needs to authenticate against Marketing Cloud APIs.
Flow: The app generates a random code_verifier, hashes it to produce code_challenge, then initiates an authorization code flow with code_challenge_method=S256. After the user authenticates, the app receives an authorization code and exchanges it for tokens by sending the original code_verifier — the server validates the hash without ever receiving a client_secret.
In Marketing Cloud Installed Packages, choose Public App component type to enable PKCE. Server-to-Server components use client credentials flow (no PKCE needed). Web App components use standard authorization code flow with a client_secret stored server-side.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.