Loading

Salesforce Retirement of OAuth 2.0 Username-Password Flow and Impact on Own from Salesforce Products

Date de publication: Sep 4, 2026
Description

Salesforce will stop supporting the OAuth 2.0 username-password flow for connected apps. This update will break all connected app integrations that use this flow.

This update improves security and better protects your Salesforce data. The username-password flow directly passes the user's credentials in HTTP requests, which presents security risks.

All connected app integrations that use the username-password flow will no longer work. Salesforce recommends updating your integrations to use a more secure flow. For end user login and authorization, use the OAuth 2.0 web-server flow with the Proof Key for Code Exchange (PKCE) extension, which adds a dynamically generated secret to each login request to prevent interception. For server-to-server integrations, use the OAuth 2.0 client credentials flow.

Own from Salesforce will implement these changes to ensure the highest level of trust and protection for our customers. Our Engineering team is already actively working on a solution to ensure we are fully compliant before the enforcement deadlines. To meet these requirements, Engineering is transitioning our authentication flow from traditional refresh tokens to a JWT-based (JSON Web Token) architecture with full PKCE support.

Résolution

This section answers the question customers most often ask about this change: do I need to do anything on my end before Salesforce retires the OAuth 2.0 username-password flow? For Own from Salesforce customers, the answer is no.

What Is Changing

Salesforce is retiring the OAuth 2.0 username-password flow for connected apps. Any integration still using that flow will stop working once the retirement takes effect, because credentials are no longer accepted as a direct authentication method.

How Own from Salesforce Is Responding

Own from Salesforce is moving its authentication architecture from traditional refresh tokens to a JWT-based (JSON Web Token) model with full PKCE (Proof Key for Code Exchange) support. This aligns Own with Salesforce's recommended OAuth 2.0 web-server flow for end-user logins and the OAuth 2.0 client credentials flow for server-to-server integrations.

What Customers Need to Do

These changes are designed to be entirely seamless for customers and will not require any action on your end. Own's Engineering team is handling the migration ahead of Salesforce's enforcement deadlines, so your existing connections to Own from Salesforce will continue working without interruption.

Numéro d’article de la base de connaissances

005388592

 
Chargement
Salesforce Help | Article