OAuth PKCE (pronounced “pixy”), for which John Bradley (Ping), Naveen Agarwal (Google), and I are credited as co-authors, has been published as [RFC 7636]. It was originally called OAuth SPOP (Symmetric Proof of Posession), but because it was expanded beyond symmetric keys, it was renamed Proof Key for Code Exchange (PKCE, pronounced “pixy,” meaning a fairy), which is what it is called today.
This specification addresses the Code Interception Attack vulnerability in OAuth 2.0 [RFC6749] Public Clients. It generates an ephemeral key and uses it to perform Proof of Possession of Key. It is backward compatible with RFC6749 and easy to implement, so I believe it should be used as a matter of course from now on.
I would like to express my deepest gratitude to Eduardo Gueiros, James Manger, Brian Campbell, Mike Jones, William Dennis, and everyone who participated in reviewing the security aspects of this specification. Likewise, I would like to thank everyone in the OAuth working group, the chairs, the area directors, and everyone at the IETF involved in developing this specification.
I would also like to note that this OAuth PKCE has already been widely adopted, including by the video-site app of a certain company.
[RFC6749] Hardt, D.: The OAuth 2.0 Authorization Framework (2012), https://tools.ietf.org/html/rfc6749
Related posts

JSON Web Key (JWK) Thumbprint Has Been Published as RFC 7638
“JSON Web Key (JWK) Thumbprint,” for which Mike Jones and I are credited as co-authors, has been published as [RFC 7638]. This specification defines a method…

OAuth-J Announces OAuth Optical Transport Profile for Network Resilience, Applying Cryptocurrency Technology
【AF Wire, Tokyo】The OAuth Foundation Japan (OAuth-J) announced on April 1, 2018 that it would begin developing the OAuth Optical Transport Profile (OAuth OTP), a new…

Happy New Year
Thank you very much for all your support during the past year. In 2015, almost as though marking my 50th birthday, a succession of standards on…
