# pkce-challenge

> Generate or verify a Proof Key for Code Exchange (PKCE) challenge pair

Latest version **6.0.0** (published 2026-02-01) · MIT license · 0 weekly downloads

## Install

```sh
npm install pkce-challenge
pnpm add pkce-challenge
yarn add pkce-challenge
bun add pkce-challenge
```

## Health

**Score 60/100 (C)** — status: stable.

Positive: esm support; no vulnerabilities; has provenance; high maintenance score.

Warnings: low downloads; no types.

## Facts

| | |
|---|---|
| Version | 6.0.0 |
| Published | 2026-02-01 |
| First published | 2019-01-11 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM |
| Node | >=16.20.0 |
| Dependencies | 0 |
| Unpacked size | 23.2 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 91 |
| Author | crouchcd |
| Maintainers | crouchcd |
| Keywords | PKCE, oauth2 |

## Links

- npm: https://www.npmjs.com/package/pkce-challenge
- Repository: https://github.com/crouchcd/pkce-challenge
- Homepage: https://github.com/crouchcd/pkce-challenge#readme
- Issues: https://github.com/crouchcd/pkce-challenge/issues
- npm.io page: https://npm.io/package/pkce-challenge

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 6.0.0 (latest) — 2026-02-01
- 5.0.1 — 2025-11-23
- 5.0.0 — 2025-03-31
- 4.1.0 — 2024-01-26
- 4.0.1 — 2023-05-11
- 4.0.0 — 2023-05-11
- 3.1.0 — 2023-03-29
- 3.0.0 — 2022-03-29
- 2.2.0 — 2021-05-20
- 2.1.0 — 2019-12-20
- 2.0.0 — 2019-10-19
- 1.0.3 — 2019-06-06
- 1.0.2 — 2019-01-11
- 1.0.1 — 2019-01-11
- 1.0.0 — 2019-01-11

## README

# pkce-challenge

Generate or verify a Proof Key for Code Exchange (PKCE) challenge pair.

Read more about [PKCE](https://www.oauth.com/oauth2-servers/pkce/authorization-request/).

## Installation

```bash
npm install pkce-challenge
```

## Usage

Default length for the verifier is 43

```js
import pkceChallenge from "pkce-challenge";

await pkceChallenge();
```

gives something like:

```js
{
    code_verifier: 'u1ta-MQ0e7TcpHjgz33M2DcBnOQu~aMGxuiZt0QMD1C',
    code_challenge: 'CUZX5qE8Wvye6kS_SasIsa8MMxacJftmWdsIA_iKp3I',
    code_challenge_method: 'S256'
}
```

### Specify a verifier length

```js
const challenge = await pkceChallenge(128);

challenge.code_verifier.length === 128; // true
```

### Specify a challenge method

The library supports two challenge methods:
- `S256` (default): SHA-256 hashing
- `plain`: No hashing (verifier equals challenge)

```js
// Use S256 method (default)
const challenge = await pkceChallenge(43, "S256");
challenge.code_challenge_method === "S256"; // true

// Use plain method
const plainChallenge = await pkceChallenge(43, "plain");
plainChallenge.code_challenge_method === "plain"; // true
plainChallenge.code_challenge === plainChallenge.code_verifier; // true
```

### Challenge verification

```js
import { verifyChallenge } from "pkce-challenge";

(await verifyChallenge(challenge.code_verifier, challenge.code_challenge)) ===
  true; // true

// Verify with specific method
(await verifyChallenge(
  challenge.code_verifier,
  challenge.code_challenge,
  "S256"
)) === true; // true
```

### Challenge generation from existing code verifier

```js
import { generateChallenge } from "pkce-challenge";

(await generateChallenge(challenge.code_verifier)) === challenge.code_challenge; // true

// Generate with specific method
(await generateChallenge(challenge.code_verifier, "S256")) ===
  challenge.code_challenge; // true
```

---
_Source: https://npm.io/package/pkce-challenge · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
