HAIP currently requires PKCE, but doesn't actually require that servers reject requests without PKCE. As was done in a similar discussion in VCI ( https://github.com/openid/OpenID4VCI/pull/534 ) we should consider just mandating FAPI2 instead.