Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More

Salesforce Retirement of OAuth 2.0 Username-Password Flow and impact on Own Products

Publish Date: Jul 7, 2026
Description

Salesforce will stop supporting the OAuth 2.0 username-password flow for connected apps. This update will break all connected app integrations that use this flow.

This update improves security and better protects your Salesforce data. The username-password flow directly passes the user’s credentials in HTTP requests, which presents security risks.

All connected app integrations that use the username-password flow will no longer work. Salesforce recommends to update your integrations to use a more secure flow. For end user login and authorization, use the OAuth 2.0 web-server flow with the Proof Key for Code Exchange (PKCE) extension. For server-to-server integrations, use the OAuth 2.0 client credentials flow. 

Own will implement these changes to ensure the highest level of trust and protection for our customers. Our Engineering team is already actively working on a solution to ensure we are fully compliant before the enforcement deadlines. To meet these requirements, Engineering is transitioning our authentication flow from traditional refresh tokens to a JWT-based (JSON Web Token) architecture with full PKCE support.

Resolution

Theses changes will be entirely be seamless and will not require any changes from customer side.

Additional Resources

Retirement of OAuth 2.0 Username-Password Flow for Connected Apps (Release Update)
https://help.salesforce.com/s/articleView?id=release-notes.rn_security_unpw_flow_retirement.htm&release=262&type=5

Knowledge Article Number

005388592

 
Loading
Salesforce Help | Article