Salesforce will stop supporting the OAuth 2.0 username-password flow for connected apps. This update will break all connected app integrations that use this flow.
This update improves security and better protects your Salesforce data. The username-password flow directly passes the user's credentials in HTTP requests, which presents security risks.
All connected app integrations that use the username-password flow will no longer work. Salesforce recommends updating your integrations to use a more secure flow. For end user login and authorization, use the OAuth 2.0 web-server flow with the Proof Key for Code Exchange (PKCE) extension, which adds a dynamically generated secret to each login request to prevent interception. For server-to-server integrations, use the OAuth 2.0 client credentials flow.
Own from Salesforce will implement these changes to ensure the highest level of trust and protection for our customers. Our Engineering team is already actively working on a solution to ensure we are fully compliant before the enforcement deadlines. To meet these requirements, Engineering is transitioning our authentication flow from traditional refresh tokens to a JWT-based (JSON Web Token) architecture with full PKCE support.
This section answers the question customers most often ask about this change: do I need to do anything on my end before Salesforce retires the OAuth 2.0 username-password flow? For Own from Salesforce customers, the answer is no.
Salesforce is retiring the OAuth 2.0 username-password flow for connected apps. Any integration still using that flow will stop working once the retirement takes effect, because credentials are no longer accepted as a direct authentication method.
Own from Salesforce is moving its authentication architecture from traditional refresh tokens to a JWT-based (JSON Web Token) model with full PKCE (Proof Key for Code Exchange) support. This aligns Own with Salesforce's recommended OAuth 2.0 web-server flow for end-user logins and the OAuth 2.0 client credentials flow for server-to-server integrations.
These changes are designed to be entirely seamless for customers and will not require any action on your end. Own's Engineering team is handling the migration ahead of Salesforce's enforcement deadlines, so your existing connections to Own from Salesforce will continue working without interruption.
005388592

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.