OAuth PKCE Handbook
A queryable handbook for authorization-code + PKCE, redirect URIs, refresh rotation, and SPA token storage — written for people who ship login.
Portable policy knowledge for local retrieval.
OAuth PKCE Handbook is original integration guidance mapped to RFC 6749 and RFC 7636.
Public clients use authorization code + PKCE. Implicit is retired. Secrets do not live in a SPA.
The included agent metadata is never executed by Knolo Hub.
Intended use
Grounding OAuth and OIDC integration choices. Lookup when adding PKCE, storing tokens, or reviewing a redirect URI.
Out of scope
This pack does not issue tokens, talk to an identity provider, or store secrets. It does not run a browser or a shell.
Sources
Sample questions
This Knowledge Image contains prompts, tool policy, namespace grants, or other agent registry metadata.
Mounting the pack for retrieval does not execute tools. Applying these policies affects your application only if your host explicitly honors them.
Credentials must never be stored inside a pack.