Loading

Salesforce Retirement of OAuth 2.0 Username-Password Flow and impact on Own Products

Date de publication: Jul 7, 2026
Description

Salesforce will stop supporting the OAuth 2.0 username-password flow for connected apps. This update will break all connected app integrations that use this flow.

This update improves security and better protects your Salesforce data. The username-password flow directly passes the user’s credentials in HTTP requests, which presents security risks.

All connected app integrations that use the username-password flow will no longer work. Salesforce recommends to update your integrations to use a more secure flow. For end user login and authorization, use the OAuth 2.0 web-server flow with the Proof Key for Code Exchange (PKCE) extension. For server-to-server integrations, use the OAuth 2.0 client credentials flow. 

Own will implement these changes to ensure the highest level of trust and protection for our customers. Our Engineering team is already actively working on a solution to ensure we are fully compliant before the enforcement deadlines. To meet these requirements, Engineering is transitioning our authentication flow from traditional refresh tokens to a JWT-based (JSON Web Token) architecture with full PKCE support.

Résolution

Theses changes will be entirely be seamless and will not require any changes from customer side.

Ressources supplémentaires

Retirement of OAuth 2.0 Username-Password Flow for Connected Apps (Release Update)
https://help.salesforce.com/s/articleView?id=release-notes.rn_security_unpw_flow_retirement.htm&release=262&type=5

Numéro d’article de la base de connaissances

005388592

 
Chargement
Salesforce Help | Article