Term Kind Topic What it is
Authorization Code Flow with PKCE PKCE protocol OAuth 2.0 & OIDC The OAuth flow recommended for all client types, in which an authorisation code is exchanged for tokens using a proof key that binds the exchange to the original requester.
JSON Web Token JWT protocol Security Architecture A signed, self-contained token carrying claims, which a service can validate locally without calling the issuer.
JWKS JSON Web Key Set protocol Tokens & JWTs A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to survive key rotation.
OAuth 2.0 protocol Security Architecture An authorisation framework that lets an application obtain scoped, delegated access to a resource without handling the user's credentials.
OpenID Connect OIDC protocol Security Architecture An identity layer over OAuth 2.0 that adds a signed ID token asserting who the user is and how they authenticated.
Token Introspection protocol OAuth 2.0 & OIDC Asking the authorisation server whether a token is currently valid, rather than validating it locally from its signature.