L26 · OAUTH 2.0
Break PKCE on purpose
Exchange a code with the wrong verifier, then with the right one.
Planned
Steps
Exchange a code with a verifier that does not match the challenge.
What the server will check: The exchange was rejected as a PKCE mismatch.
Start again and exchange a new code with the matching verifier.
What the server will check: A successful exchange for the same client.
Only the application that started the flow knows the verifier, so a stolen code is useless on its own.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- The lab callback page
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.