A security extension to the OAuth 2.0 authorization code flow (RFC 7636) that prevents authorization code interception attacks by requiring a dynamically generated code verifier — essential for mobile and single-page applications.
Category: authentication. Part of the Identity Technologist Glossary — 158+ practitioner-grade definitions covering identity verification, KYC/AML, biometrics, fraud prevention, and compliance. See all terms at https://identitytechnologist.com/glossary.