# The Multivac — Evaluation Report

**Evaluation ID:** EVAL-20260402-141544
**Date:** Apr 02, 2026
**Category:** code
**Question ID:** CODE-022

---

## Question

Implement the OAuth 2.0 Authorization Code flow with PKCE (Proof Key for Code Exchange) from scratch in Python. Include: code verifier/challenge generation, authorization URL construction, token exchange, token refresh, and secure token storage. Explain why PKCE prevents authorization code interception attacks.

---

## Winner

**Grok 4.20** (openrouter)
- Winner Score: 8.90
- Matrix Average: 7.42
- Total Judgments: 89

---

## Rankings

| Rank | Model | Provider | Avg Score | Judgments |
|------|-------|----------|-----------|----------|
| 1 | Grok 4.20 | openrouter | 8.90 | 8 |
| 2 | Gemini 3 Flash Preview | Google | 8.24 | 9 |
| 3 | GPT-5.4 | openrouter | 7.75 | 9 |
| 4 | DeepSeek V4 | openrouter | 7.58 | 9 |
| 5 | GPT-OSS-120B | OpenAI | 7.57 | 9 |
| 6 | MiniMax M2.5 | openrouter | 7.53 | 9 |
| 7 | MiMo-V2-Flash | Xiaomi | 7.39 | 9 |
| 8 | Claude Sonnet 4.6 | openrouter | 7.14 | 9 |
| 9 | Claude Opus 4.6 | openrouter | 6.62 | 9 |
| 10 | Gemini 3.1 Pro | openrouter | 5.47 | 9 |

---

## 10×10 Judgment Matrix

Rows = Judge, Columns = Respondent. Self-judgments excluded (—).

| Judge ↓ / Resp → | Gemini 3.1 Pro | GPT-5.4 | Claude Opus | Claude Sonnet | Grok 4.20 | DeepSeek V4 | GPT-OSS-120B | Gemini 3 | MiniMax M2.5 | MiMo-V2-Flash |
|---|---|---|---|---|---|---|---|---|---|---|
| Gemini 3.1 Pro | — | 5.3 | 6.3 | 6.5 | 9.8 | 6.5 | 6.4 | 7.5 | 6.3 | 6.3 |
| GPT-5.4 | 2.3 | — | 2.9 | 4.1 | 8.0 | 6.8 | 5.5 | 7.8 | 3.9 | 4.8 |
| Claude Opus | 4.3 | 7.8 | — | 6.5 | 8.2 | 6.6 | 7.0 | 8.4 | 7.7 | 6.5 |
| Claude Sonnet | 4.0 | 8.0 | 7.3 | — | · | 7.6 | 8.0 | 8.4 | 7.5 | 7.6 |
| Grok 4.20 | 5.8 | 8.4 | 6.0 | 7.7 | — | 7.5 | 8.4 | 8.4 | 8.4 | 8.6 |
| DeepSeek V4 | 7.0 | 8.8 | 8.6 | 9.0 | 9.6 | — | 8.6 | 8.8 | 8.7 | 9.3 |
| GPT-OSS-120B | 5.9 | 7.0 | 4.5 | 5.8 | 8.8 | 7.8 | — | 8.6 | 7.5 | 7.4 |
| Gemini 3 | 7.7 | 8.8 | 9.3 | 9.0 | 9.8 | 9.4 | 8.6 | — | 9.4 | 9.4 |
| MiniMax M2.5 | 3.4 | 7.0 | 6.0 | 7.1 | 8.0 | 7.5 | 7.0 | 7.6 | — | 6.6 |
| MiMo-V2-Flash | 8.8 | 8.6 | 8.8 | 8.6 | 9.0 | 8.6 | 8.6 | 8.6 | 8.6 | — |

---

## Methodology

- **10×10 Blind Peer Matrix:** All models answer the same question, then all models judge all responses.
- **5 Criteria:** Correctness, completeness, clarity, depth, usefulness (each scored 1–10).
- **Self-judgments excluded:** Models do not judge their own responses.
- **Weighted Score:** Composite of all 5 criteria.

---

## Citation

The Multivac (2026). Blind Peer Evaluation: CODE-022. app.themultivac.com

## License

Open data. Free to use, share, and build upon. Please cite The Multivac when using this data.

Download raw JSON: https://app.themultivac.com/api/evaluations/EVAL-20260402-141544/results
Full dataset: https://app.themultivac.com/dashboard/export
