This page is for Authlete 2.x. For current (3.0) documentation, see this page.
Requiring clients to specify “S256” when using PKCE for their authorization requests
Authlete has a feature to require OAuth 2.0 clients to specify a value of “S256” for “code_challenge_method” parameter when using PKCE (RFC 7636) for their authorization requests. You can enable this feature by opening “Edit Service” and choosing “Required” at “S256 for Code Challenge Method” setting in “Authorization Endpoint” section under “Authorization” tab. The default selection is “Not Required.”