PKCE Generator — Generate OAuth 2.0 PKCE Code Verifier & Challenge
Generate PKCE code_verifier and code_challenge pairs for OAuth 2.0 Authorization Code + PKCE flow — 100% client-side using Web Crypto API.
Jump to tool ↓Generates a cryptographically random code_verifier (32 bytes → Base64URL) and computes code_challenge = SHA-256(verifier) → Base64URL using the Web Crypto API.
Frequently Asked Questions
PKCE for Secure OAuth 2.0
PKCE (RFC 7636) was introduced to secure OAuth 2.0 Authorization Code flows in scenarios where clients cannot store a client secret securely. This includes native mobile apps, single-page applications, and desktop applications.
The flow works as follows: the client generates a random code_verifier, computes code_challenge = BASE64URL(SHA256(code_verifier)), and sends the challenge in the authorization request. When exchanging the authorization code for tokens, the client sends the original code_verifier. The server verifies the challenge.
This prevents authorization code interception attacks — even if an attacker intercepts the authorization code (e.g., via a malicious app registered to the same redirect URI), they cannot exchange it for tokens without the code_verifier. The verifier is sent to the authorization server at the token endpoint, but is not included in the earlier authorization request.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
PKCE Code Verifier and Challenge: S256 Example
Generate a compliant PKCE code verifier, derive its S256 challenge, and place each value in the correct OAuth authorization and token requests.
AuthenticationWhat Is OAuth 2.0 and How Does It Work?
OAuth 2.0 lets apps access resources on your behalf without sharing your password. Learn the roles, the authorization flow, access vs refresh tokens, and OAuth vs OIDC.
AuthenticationTOTP vs HOTP: How Two-Factor Codes Actually Work
TOTP and HOTP are the two algorithms behind nearly every 2FA app. Here's how each one works, why TOTP won, and what to do when codes stop matching.
AuthenticationJWT vs OAuth: What's the Difference?
JWT and OAuth are often confused — one is a token format, the other is an authorization framework. Here's exactly how they differ and how they work together.