<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On 20 Aug 2020, at 0.23, Wessel, Keith <<a href="mailto:kwessel@illinois.edu" class="">kwessel@illinois.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">I don't see anything in the OIDC extension docs about this, so I figured I'd ask. Does the OIDC extension support PKCE and the use of a code_challenge parameter in place of a client secret in an authorization request? This is, obviously, in the context of mobile apps and not having to embed the client secret in the app.<br class=""></div></div></blockquote><br class=""></div><div>Yes, PKCE is supported since 1.1.0. I’ve just added a case example at the end of the following Wiki-page:</div><div><br class=""></div><div><a href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO" class="">https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO</a></div><div><br class=""></div><div>BR,</div><div>Henri.</div></body></html>