RFC 7636: Proof Key for Code Exchange by OAuth Public Clients
In plain English — editorial summary, not part of the RFC
OAuth 2.0 public clients utilizing the Authorization Code Grant are susceptible to the authorization code interception attack. This specification describes the attack as well as a technique to mitigate against the threat through the use of Proof Key for Code Exchange (PKCE, pronounced "pixy").
Document record
- Document ID
- RFC7636
- Published
- September 2015
- Authors
- N. Sakimura; J. Bradley; N. Agarwal
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 20
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7591OAuth 2.0 Dynamic Client Registration ProtocolCurrent
July 2015
- RFC 7817Updated Transport Layer Security (TLS) Server Identity Check Procedure for Email-Related ProtocolsCurrent
March 2016
- RFC 7029Extensible Authentication Protocol (EAP) Mutual Cryptographic BindingCurrent
October 2013
- RFC 8314Cleartext Considered Obsolete: Use of Transport Layer Security (TLS) for Email Submission and AccessUpdated
January 2018
- RFC 6819OAuth 2.0 Threat Model and Security ConsiderationsUpdated
January 2013
- RFC 6813The Network Endpoint Assessment (NEA) Asokan Attack AnalysisCurrent
December 2012
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 9200Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework (ACE-OAuth)Current
August 2022
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?