Set MFA Login Requirements for API Access (Salesforce Orgs)
Multi-factor authentication isn’t required for system integration login types via the
API. But you can add extra protection for API access with the Multi-Factor Authentication for
API Logins permission. With this permission enabled, users are required to complete a second
authentication challenge to access Salesforce APIs. API access includes the use of client
applications such as the Data Loader and connected apps.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions
Needed
To edit system permissions in profiles:
Manage Profiles and Permission Sets
To enable this feature:
Multi-Factor Authentication for User Interface Logins
Important
Salesforce enforces MFA requirements in the summer of 2026. See these articles for more
information and detailed rollout timelines.
The Multi-Factor Authentication for User Interface Logins permission is a prerequisite for
the Multi-Factor Authentication for API Logins permission. Before the Multi-Factor
Authentication for API Logins permission takes effect, users must access Salesforce through
the UI and complete MFA using Salesforce Authenticator or a third-party authenticator app.
After users have completed MFA through the UI, they can use time-based, one-time passwords
(TOTPs) generated by their authenticator app for API logins.
Note You can’t assign the Multi-Factor Authentication for User
Interface Logins permission to users with the Salesforce Limited Access – Free license.
We're working to resolve this issue.
For developer tools that use API logins, users log in with a security token or TOTP instead
of Salesforce Authenticator when MFA is enabled.
Note API Only users can access the UI to register for MFA only. After a successful
registration, API Only users can no longer access the UI.
For connected apps, only these standard OAuth 2.0 flows support API logins with the high
assurance MFA session security level.
Web server flow
Refresh token flow
User-agent flow
JSON Web Token (JWT) bearer flow
All other standard OAuth 2.0 flows block API logins with the high assurance MFA session
security level. It’s possible that users are prompted to verify their identity twice with
high assurance MFA during an OAuth approval flow. The first challenge occurs in the UI
session. The second challenge happens when the access token is bridged into the UI. This
second challenge is triggered because the high assurance MFA session security level isn’t
transferred to the access token. For more information, see Session Security Levels.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.