<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-oauth-spop" target="https://datatracker.ietf.org/doc/html/draft-ietf-oauth-spop-15">
   <front>
      <title>Proof Key for Code Exchange by OAuth Public Clients</title>
      <author initials="N." surname="Sakimura" fullname="Nat Sakimura">
         <organization>Nomura Research Institute</organization>
      </author>
      <author initials="J." surname="Bradley" fullname="John Bradley">
         <organization>Ping Identity</organization>
      </author>
      <author initials="N." surname="Agarwal" fullname="Naveen Agarwal">
         <organization>Google</organization>
      </author>
      <date month="July" day="10" year="2015" />
      <abstract>
	 <t>OAuth 2.0 public clients utilizing the Authorization Code Grant are susceptible to the authorization code interception attack.  This specification describes the attack as well as a technique to mitigate against the threat through the use of Proof Key for Code Exchange (PKCE, pronounced &quot;pixy&quot;).
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-oauth-spop-15" />
   
</reference>
