OAuth2 Proof Key for Code Exchange (PKCE) Support?
Hello,
Typical HubSpot OAuth2 app authentication includes the app passing HubSpot a client secret. However, some types of applications do not have a way to securely store secrets (such as Singe Page Applications). In cases like these, it is desirable to use Proof Key for Code Exchange (PKCE) for OAuth2 which avoids secrets.
Is there a way to use PKCE with HubSpot's APIs?
(You've probably already guessed, but I'm in a situation where the integration I have runs in a tool that does not provide an way to keep a secret secure, so I'd like to avoid handling the secret altogether. :-))
OAuth2 Proof Key for Code Exchange (PKCE) Support?
Hi, @IntegrationDev👋 Thanks for reaching out. Based on my search of my resources and our developer documentation, HubSpot's APIs do not support the PKCE (Proof Key for Code Exchange) extension for OAuth 2.0.
I'd like to invite some of our community members to the converstaion — hey @ChrisoKlepke@louischausse@Teun, do you have any thoughts or other workaround suggestions for @IntegrationDev?
Thank you for taking a look! — Jaycee
Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.