OAuth PKCE Generator
Generate a cryptographically random PKCE code verifier and its S256 code challenge, plus a state parameter and nonce, with the full authorisation and token request they belong in.
Last reviewed by the Radiatus Cloud team
Build the requests
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Closing the authorisation code interception hole
The OAuth authorisation code flow returns a code to the client's redirect URI, which the client then exchanges for tokens. On a mobile or single page application there is no client secret to protect that exchange, so an attacker who intercepts the code, historically through a malicious app registering the same custom URI scheme, can exchange it themselves. Proof Key for Code Exchange, RFC 7636, fixes this by having the client commit to a secret before the authorisation request and prove knowledge of it at the token request.
How the three values fit together
The client generates a random code verifier, hashes it with SHA-256 and base64url encodes the result to produce the code challenge. The challenge goes in the authorisation request; the verifier is held privately and sent with the token request. The authorisation server hashes the verifier it receives and compares it to the challenge it stored. An attacker holding only the intercepted code cannot complete the exchange without the verifier, which never travelled over the channel they compromised.
Use S256 and generate properly
The specification permits a plain method where the challenge equals the verifier, which provides no protection at all and exists only for constrained devices that cannot compute SHA-256. Always use S256. The verifier must be between 43 and 128 characters from an unreserved character set and must come from a cryptographic random source. PKCE is now required for all clients in the OAuth 2.1 draft, not just public ones, because it also mitigates authorisation code injection against confidential clients.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Do I need PKCE for a confidential client?
Yes under current guidance. OAuth 2.1 and the security best current practice require it for all clients, because beyond protecting public clients it also mitigates authorisation code injection attacks that affect confidential ones.
What is the difference between S256 and plain?
S256 sends the SHA-256 hash of the verifier as the challenge; plain sends the verifier itself. Plain provides no protection because an attacker who intercepts the authorisation request learns the verifier. Only use plain if the device genuinely cannot compute SHA-256.
How long should the code verifier be?
Between 43 and 128 characters from the unreserved set of letters, digits, hyphen, period, underscore and tilde. The specification recommends 32 bytes of entropy base64url encoded, which produces 43 characters.
Is state still needed with PKCE?
Yes. They defend against different things. PKCE protects the code exchange; state protects against cross site request forgery on the redirect and carries application context. A nonce is additionally required for OpenID Connect ID tokens.
Are these values generated securely here?
They come from the browser crypto.getRandomValues API, which is a cryptographically secure random source. Everything is generated locally and nothing is transmitted. In production, generate them in your own client rather than copying values from anywhere.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Press generate to create a verifier, challenge, state and nonce for an OAuth authorisation request.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.