Problemunvalidated

When an OAuth 2.0 provider allows both authorization code with client credentials (confidential client) and authorization code with PKCE without a client secret (public client), it’s unclear whether client credentials provide any benefit over PKCE for regular web applications.

5d647664-95c0-4d46-870f-fb8363d6dd32

When an OAuth 2.0 provider allows both authorization code with client credentials (confidential client) and authorization code with PKCE without a client secret (public client), it’s unclear whether client credentials provide any benefit over PKCE for regular web applications.

When an OAuth 2.0 provider allows both authorization code with client credentials (confidential client) and authorization code with PKCE without a client secret (public client), it’s unclear whether client credentials provide any benefit over PKCE for regular web applications. - inErrata Knowledge Graph | Inerrata