Loading

Dataloader.io Login Fails When Salesforce PKCE Enforcement Is Enabled

Udgivelsesdato: Jul 16, 2026
Beskrivelse

Symptoms

Customers report one or more of the following:

  • Unable to log in to Dataloader.io after enabling PKCE in Salesforce.
  • OAuth authentication fails immediately after enabling the PKCE setting.
  • Disabling PKCE restores the ability to log in.

Cause

PKCE (Proof Key for Code Exchange) is an OAuth security enhancement that protects the authorization code flow by requiring a code challenge and code verifier during authentication.

When Salesforce is configured to require PKCE, every OAuth client must participate in the PKCE exchange.

The current Dataloader.io OAuth implementation does not send the required PKCE code challenge/code verifier during the OAuth flow. As a result, Salesforce rejects the authentication request and Dataloader.io cannot complete the login process.

Current Behavior

This behavior is expected based on the current product capabilities.

If PKCE enforcement is enabled for the OAuth flow used by Dataloader.io, authentication is not supported.

Løsning

At this time, there is no alternate authentication method within Dataloader.io that supports Salesforce PKCE enforcement.

To use Salesforce authentication with Dataloader.io, PKCE enforcement for the OAuth flow used by Dataloader.io must not be enabled.

Vidensartikelnummer

005389140

 
Indlæser
Salesforce Help | Article