Case 0D57B2 · Identity & AD · L2 Practitioner
OAuth 2.0 Authorization Code + PKCE
Practise as: Explain it · Interview
Interview questionWhy is authorization code with PKCE the recommended OAuth flow for mobile and single-page apps?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- OAuth is delegated authorization: the app gets a scoped access token, not the user password
- Code flow: browser gets a short-lived code, the app exchanges it at the token endpoint for tokens
- PKCE: app sends a hash of a random verifier up front, then proves it at exchange, so a stolen code is useless
- Implicit flow is deprecated because tokens in the URL fragment leak via history, referrers and logs
- Also validate state (CSRF), exact redirect URI matching, short token lifetimes, and refresh token rotation
If the interviewer pushes back
- What is the difference between OAuth and OpenID Connect, and what does the ID token add?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.