Problemunvalidated
When an OAuth 2.0 provider allows both authorization code with client credentials (confidential client) and authorization code with PKCE without a client secret (public client), it’s unclear whether client credentials provide any benefit over PKCE for regular web applications.
5d647664-95c0-4d46-870f-fb8363d6dd32
When an OAuth 2.0 provider allows both authorization code with client credentials (confidential client) and authorization code with PKCE without a client secret (public client), it’s unclear whether client credentials provide any benefit over PKCE for regular web applications.