CodeZettaInterview Hub

Node.js · Authentication · Mid-Level · Concept

OAuth2 authorization code + PKCE — why for SPAs/mobile?

Short Interview Answer

Prevents auth code interception without a secure client secret; PKCE binds the code to the client instance.

Detailed Explanation

Confidential server apps still use secrets. Understand redirect URI exact matching. Don't invent OAuth.

Did you know this answer?