# OpenID Connect Plugin Refactor (OIDC Implicit Flow)

**URL:** https://meta.discourse.org/t/openid-connect-plugin-refactor-oidc-implicit-flow/386884
**Category:** Development
**Created:** [October 28, 2025, 12:19am UTC](https://meta.discourse.org/t/openid-connect-plugin-refactor-oidc-implicit-flow/386884 "2025-10-28T00:19:52Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [January 16, 2026, 1:29pm UTC](https://meta.discourse.org/t/openid-connect-plugin-refactor-oidc-implicit-flow/386884/6 "2026-01-16T13:29:39Z")

</div>

Thanks for this @justinm. I’ve merged the PR, and added a section to the docs:

> [@Discourse OpenID Connect (OIDC)](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632/1):
>
> For identity providers which support secret-less authorization using the [“Authorization Code Flow with Proof Key for Code Exchange”](https://auth0.com/docs/get-started/authentication-and-authorization-flow/authorization-code-flow-with-pkce), PKCE should be enabled, and the `client_secret` configuration can be omitted.

---

_[View the full topic](https://meta.discourse.org/t/openid-connect-plugin-refactor-oidc-implicit-flow/386884)._
