Prompt
Do I need PKCE for mobile OAuth?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Usually yes — for mobile OAuth, you should use PKCE.
Why
Mobile apps are generally considered public clients because they can’t safely store a client secret. PKCE helps protect the authorization code flow against code interception and replay attacks.
When PKCE is recommended/expected
- Native mobile apps (iOS, Android)
- SPA/mobile web views
- Any client that cannot securely keep a client secret
When it may not be needed
- If you’re using a backend server that handles the OAuth flow and keeps the client secret securely, PKCE may be optional depending on the provider.
- Some providers now require PKCE even for confidential clients.
Best practice
For mobile apps, use:
- Authorization Code Flow + PKCE
- Avoid the implicit flow
- Prefer the system browser / ASWebAuthenticationSession / Custom Tabs rather than embedded webviews
If you want, I can also give you the exact OAuth flow for iOS or Android.