What is PKCE, and why does it matter?
Suggested answer
PKCE — Proof Key for Code Exchange — closes the gap that makes the plain authorisation code flow unsafe for a client that cannot keep a secret.
The client generates a random code verifier, hashes it into a code challenge, and sends the challenge with the authorisation request. When it later redeems the authorisation code, it must present the original verifier. Salesforce hashes it and compares. So an attacker who intercepts the authorisation code — through a malicious app registered for the same custom URL scheme, or a leaky redirect — cannot exchange it, because they do not have the verifier.
Why it matters practically: it is what lets a mobile or single-page application use the authorisation code flow at all. The alternative used to be embedding a client secret in a distributed binary, which is not a secret, or using the implicit flow, which put the access token in a URL where it ends up in history and referrer headers. PKCE removes the need for either.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.