Salesforce has removed support for the OAuth 2.0 Device Flow in the default Salesforce CLI (Command Line Interface) Connected App. This change is permanent — there will be no exceptions or extensions.
This change is part of Salesforce's commitment to making products and services secure-by-default.
Effective Date: Starting August 28, 2025, new and existing authorizations to any org using the OAuth 2.0 Device Flow with the default Salesforce CLI connected app will be blocked.
Who Is Affected: Users who use the org login device CLI command with the default Salesforce CLI connected app. Starting August 28, 2025, these authorizations will be blocked.
Announcement
https://github.com/forcedotcom/cli/issues/3368
Use the Web Server Flow for interactive authentication with browser access:
sf org login webUse the JWT (JSON Web Token) Bearer Flow for headless environments such as CI/CD pipelines where browser authentication is not available:
sf org login jwtYou cannot work around this restriction by re-enabling the Device Flow in a custom connected app, because the Enable for Device Flow option in the API (Enable OAuth Settings) section has been permanently disabled by Salesforce. Additionally, Org Admins must now install the Salesforce CLI connected app themselves — this can no longer be done by standard users.
005135030

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.