Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

Understanding the usage of the web api

Solved!

Understanding the usage of the web api

Hi, I want to use the web api from spotify for developers but I want to make sure of some things about it. I read the docs, but I want to be sure that I understood them clearly.

 

If I go with authorization code with PKCE that means I won't need the client secret no more in the entire app? After that will I be able to use the access token to get the user data and only use the client id to get all the necessary data from spotify without the use of the client secret?

 

I am asking all of this beacause I want to make a web music player working only on the front-end side without backend and I want to be sure that I won't expose publicly the client secret.

Reply

Accepted Solutions
Marked as solution

Yes, you can use PKCE without client secret and without a back-end.

XimzendSpotify Star
Help others find this answer and click "Accept as Solution".
If you appreciate my answer, maybe give me a Like.
Note: I'm not a Spotify employee.

View solution in original post

2 Replies
Marked as solution

Yes, you can use PKCE without client secret and without a back-end.

XimzendSpotify Star
Help others find this answer and click "Accept as Solution".
If you appreciate my answer, maybe give me a Like.
Note: I'm not a Spotify employee.

Thank you for confirming!

Suggested posts

Type a product name