> As a transition, is there a way to allow a given client to use > standard token-based auth _or_ PKCE? I don't think the protocol allows for it, but that would be more a Henri question. I don't think it's possible now certainly, but I don't know if that's a choice or just a given. -- Scott