> ## Documentation Index
> Fetch the complete documentation index at: https://developers.pleo.io/llms.txt
> Use this file to discover all available pages before exploring further.

# PKCE and Secured Patterns

export const RememberCallout = ({title, children}) => <div className="callout-box callout-remember">
    <div className="callout-row">
      <span className="callout-icon">
        <svg width="22" height="22" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 256 256" fill="currentColor"><path d="M229.66,98.34,172.39,155.8c11.46,22.93-1.72,45.86-10.11,57a8,8,0,0,1-12,.83L42.34,105.76A8,8,0,0,1,43,93.85c29.65-23.92,57.4-10,57.4-10l57.27-57.46a8,8,0,0,1,11.31,0L229.66,87A8,8,0,0,1,229.66,98.34Z" opacity="0.2" /><path d="M235.32,81.37,174.63,20.69a16,16,0,0,0-22.63,0L98.37,74.49c-10.66-3.34-35-7.37-60.4,13.14a16,16,0,0,0-1.29,23.78L85,159.71,42.34,202.34a8,8,0,0,0,11.32,11.32L96.29,171l48.29,48.29A16,16,0,0,0,155.9,224c.38,0,.75,0,1.13,0a15.93,15.93,0,0,0,11.64-6.33c19.64-26.1,17.75-47.32,13.19-60L235.33,104A16,16,0,0,0,235.32,81.37ZM224,92.69h0l-57.27,57.46a8,8,0,0,0-1.49,9.22c9.46,18.93-1.8,38.59-9.34,48.62L48,100.08c12.08-9.74,23.64-12.31,32.48-12.31A40.13,40.13,0,0,1,96.81,91a8,8,0,0,0,9.25-1.51L163.32,32,224,92.68Z" /></svg>
      </span>
      <div>
        {title && <div className="callout-title">
            {title}
          </div>}
        <div className="callout-body">
          {children}
        </div>
      </div>
    </div>
  </div>;

OAuth 2.0 integrations with Pleo must follow established security patterns to protect users, credentials, and tokens throughout the authorisation lifecycle.

This page explains **why** these patterns exist and **when** they apply. Detailed configuration and implementation guidance is covered in the linked pages.

## Proof Key for Code Exchange (PKCE)

**PKCE (Proof Key for Code Exchange)** protects authorisation code flows from interception and replay attacks.

It is particularly important for **public clients**, where a client secret cannot be kept confidential.

### When PKCE Is Required

* **Mandatory** for public clients:
  * Single Page Applications (SPAs)
  * Mobile applications
* Strongly recommended for all OAuth 2.0 clients where supported

Only the **S256** code challenge method is supported. The `plain` method is not allowed.

PKCE is configured as part of your OAuth 2.0 client setup and handled automatically by most standards-compliant OAuth 2.0 libraries. See *Client Configuration* and *OAuth 2.0 Libraries and Standards* for details.

## Secure Transport (HTTPS)

All OAuth 2.0-related communication **must occur over HTTPS**, including:

* Authorisation requests
* Token exchanges
* Token refresh requests
* API calls using access tokens

Using HTTPS prevents interception of authorisation codes and tokens in transit.

<RememberCallout title="Remember">
  HTTP is permitted only for `localhost` redirect URIs in development environments.
</RememberCallout>

## Client Classification and Responsibilities

OAuth 2.0 security requirements vary depending on client type:

* **Public clients**\
  Cannot safely store a client secret. Must rely on PKCE and secure redirect handling.
* **Confidential clients**\
  Can securely store a client secret and must authenticate at the token endpoint using `client_secret_basic`.

Understanding your client type is essential before implementing OAuth 2.0 flows. This distinction is covered in the *OAuth 2.0 Authentication Workflow*.

## Avoiding Common Security Pitfalls

Integrations should **avoid** the following anti-patterns:

* Implementing OAuth 2.0 flows manually instead of using a standard library
* Storing tokens in insecure locations (for example, browser local storage)
* Reusing expired or replaced refresh tokens
* Skipping PKCE for public clients
* Hardcoding secrets in frontend or distributed code

Correct token handling and storage are covered in the Token Lifecycle section.

## Related Reading

* [Token Lifecycle](/docs/current/integration-design/auth/oauth/token-lifecycle/integration-design-auth-oauth-token-overview)
* [Client Configuration](/docs/current/integration-design/auth/oauth/getting-set-up/oauth-client-configuration)
* [OAuth 2.0 Setup Workflow Guide](/docs/current/guides/oauth-workflow-guide)
