Engineering track · 3 min
PKCE playground
Derive a code challenge from a verifier and see why an attacker fails.
The idea
1The app makes a secret verifier
A random string, kept only by the app that starts the sign-in.
2It sends only the hash
The code challenge is the SHA-256 of the verifier, base64url encoded. The hash is sent first.
3The code comes back
The authorization server returns a one-time code to the redirect URI. An attacker could intercept it.
4The verifier proves ownership
At the token endpoint the app sends the verifier. The server hashes it and compares. A thief has only the code.
Try it
Compute S256 live
Edit the verifier. The challenge is real SHA-256, computed in your browser.
This exercise needs JavaScript. Here is the answer key.
Verifier dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk hashes with SHA-256 to the code challenge.
Check yourself
1 of 3 What does the app send first?
2 of 3 What stops a thief with the code?
3 of 3 Which method does the recommended flow use?
Answer key
- What does the app send first? The code challenge. It is the hash of the verifier.
- What stops a thief with the code? They lack the verifier. The server hashes the verifier and compares.
- Which method does the recommended flow use? S256. plain is allowed only when S256 is impossible.