Should be pkce now. I think implicit flow is entirely dead? But could be wrong.
How is this possible, any examples?
> intents (on Android) and OS pinning in the client configuration of your authorization server.
Can you please elaborate?
You would hope they verified the signing of the jwt token on the backend, but seems thats too difficult for many dev's.