Just to be clear, the PKCE secret can be the same for each initiation, but in the end its goal is to ensure that the first request matches with the last one. And yes, there is "plain" PKCE method but that is just for testing. SHA256 is the default one used to obfuscate the secret.
Of course if you trust the client (no bad browser extensions, updated browser) and have good TLS settings and no MITM risk and make sure the your IDs are single-use then it seems like that should be fine.
The code_challenge == sha256(code_verifier). You will share the code_challenge at the start of the flow.
I run an authentication server and requiring PKCE allows me to make sure that XSS protection is handled for all clients.
I guess it's probably not tracking tons of IDs like tracking packet state through a network device.
Even a few million (max) UUIDv4 is probably fine then, yeah?