getsentry / getsentry/sentry

Implement PKCE support for API applications

Open
#79,647 0 comments 0 reactions 1 assignee Claimed by @BYK View on GitHub
Feature Metrics
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
22h 21m
Merged PRs (30d)
586

Description

### Problem Statement

For client-side only API applications, adding [PKCE]() support and then starting to enforce this would reduce the chances of spamming and unauthorized usage on these apps.

### Solution Brainstorm

Implement [https://oauth.net/2/pkce/]() and then start enforcing it slowly. First for all new API apps, and then for older ones too.

### Product Area

APIs

We want to define a set of [lightweight metrics]() that SDKs can automatically collect for e.g. framework, language or platform, focusing only on signals that **do NOT overlap with Tracing**. Ideally these metrics should give a quick sense of app or runtime health, … while deeper investigation will still rely on traces or profiles.

Examples**:**

* Node.js runtime metrics (e.g., event loop delay, heap usage)
* Prisma-related metrics in Next.js
* Mobile CPU / memory usage to help surface potential ANRs or app hangs

---

**Candidate Metrics (add more below)**

* …

*(please also add ideas, questions or examples in comments)*

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.