OAuth client kind ('web' or 'ios').
Authorization code from the OAuth provider.
PKCE code verifier, if applicable.
Redirect URI used during the connect step.
OAuth state parameter for CSRF protection.
OK