Revoke All JSON Web Token (JWT)-Based Access Tokens
If necessary, you can revoke all JSON Web Token (JWT)-based access tokens issued by all
external client apps and connected apps. Revoking JWT-based access tokens invalidates their
signing keys, which makes the tokens unusable.
Required Editions
Available in: both Salesforce Classic and
Lightning Experience
Connected Apps can be created in: Group, Essentials,
Professional, Enterprise, Performance, Unlimited, and
Developer Editions
Connected Apps can be installed in: All editions
Note Connected apps creation is restricted as of Spring ‘26. You can continue to use
existing connected apps during and after Spring ‘26. However, we recommend using external client apps instead. If you must continue
creating connected apps, contact Salesforce Support.
After you revoke all JWT-based access tokens, it can take up to 30
minutes for the token revocation to propagate to all systems. The token revocation process
doesn't delete associated sessions. Clients that have direct access to associated sessions,
such as clients that use hybrid OAuth flows, continue to retain access even when their tokens
are revoked.
Revoking
all JWT-based access tokens doesn’t automatically revoke all refresh tokens. To revoke
refresh tokens for an external client app, see External Client App OAuth Usage. To revoke all
refresh tokens issued by a connected app, see Manage Current OAuth Connected App Sessions. Revoke
refresh tokens for all apps that can issue JWT-based access tokens.
From Setup, in the Quick Find box, enter OAuth, and then select
OAuth and OpenID Connect Settings.
Click Revoke Tokens.
If you accept the warning, click Revoke again.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.