OAuth / OIDC Helper
Generate PKCE, state, nonce, and authorization URLs locally.
Authorization requestInputs used to build the URL
Flow valuesNever reuse these values across authorization requests
Code challenge
Generate values firstCode verifier
Generate values firstState
Generate values firstNonce
Generate values firstAuthorization URLGenerate flow values first
Waiting for input…
Authorization code + PKCE flowValues to validate at each boundary
1. ClientCreates verifier, challenge, state, and nonce before redirecting.
2. Authorization serverAuthenticates the user and returns a code with the original state.
3. Client callbackRejects a state mismatch, then exchanges the code with the verifier.
4. Token validationChecks issuer, audience, signature, time claims, and nonce before using identity claims.