The authorization code in OAuth 2 needs to get back to the client, but what if you can't read a URL on the return? I think we can use HKDF and a bit of copy-and-paste to get by.
justinsecurity.medium.com/out-of-band-...
justinsecurity.medium.com
Out-of-Band Authorization Codes
The authorization code flow of OAuth 2 (and by extension, OpenID Connect) is designed around one key assumption: on the way back from the…