Verifier format
A valid PKCE code_verifier is case-sensitive and 43 through 128 characters long. Its allowed characters are ASCII letters, digits, hyphen, period, underscore, and tilde. A client uses the verifier for one pending authorization transaction. The matching challenge goes in the authorization request, while the original verifier must be retained for the later token request.