Open cardosec

Case 0D57B2 · Identity & AD · L2 Practitioner

OAuth 2.0 Authorization Code + PKCE

Practise as: Explain it · Interview

Interview questionWhy is authorization code with PKCE the recommended OAuth flow for mobile and single-page apps?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. OAuth is delegated authorization: the app gets a scoped access token, not the user password
  2. Code flow: browser gets a short-lived code, the app exchanges it at the token endpoint for tokens
  3. PKCE: app sends a hash of a random verifier up front, then proves it at exchange, so a stolen code is useless
  4. Implicit flow is deprecated because tokens in the URL fragment leak via history, referrers and logs
  5. Also validate state (CSRF), exact redirect URI matching, short token lifetimes, and refresh token rotation

If the interviewer pushes back

  • What is the difference between OAuth and OpenID Connect, and what does the ID token add?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.