[feature]: Include PKCE Support for OIDC
@vihar is already working on this.
Since Jan 21, 2026.
- Dominant language
- TypeScript
- Stars
- 59.6k
- Forks
- 5.8k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 49
Description
Is there an existing issue for this?
- I have searched the existing issues
Summary
Currently, Plane's OIDC implementation does not support PKCE (Proof Key for Code Exchange). Modern OAuth 2.1 compliant providers (such as Better-Auth, Logto, or Keycloak 20+ in certain configurations) require PKCE for the authorization_code flow.
When attempting to connect Plane to these providers, the authentication fails because the provider expects a code_challenge in the authorization request and a code_verifier during the token exchange, which Plane does not currently seem to provide.
Why should this be worked on?
Most authentication platforms are moving towards 2.1 compliance and will not work with Plane's current OIDC implementation.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.