Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More

Tableau Server to Salesforce Connection Fails with "OAuth Refresh Token Expired" on Subsequent Attempts or Scheduled Refreshes

Publish Date: Aug 6, 2026
Description

When connecting Tableau Server to Salesforce or Salesforce Data Cloud using a newly created External Client App (ECA) where Refresh Token Rotation is enabled by default, OAuth authentication succeeds on the initial connection attempt but consistently fails on all subsequent attempts.

As a result, users encounter a Data Source Error across multiple scenarios:

  • Web Authoring: Opening or creating workbooks fails in older versions, or creating/publishing extracts fails in newer versions.
  • Test Connection: Clicking "Test Connection" under Saved Credentials succeeds on the first try, but fails on all subsequent attempts.
  • Extract Refresh Schedules: Automated scheduled refreshes and manual "Run Now" triggers fail starting from the second attempt.

Example Error Message:

Data Source Error
Unable to proceed because of an error from the data source.
Tableau has detected that the OAuth refresh token has expired. Please re-authenticate using new credentials. Contact your Tableau administrator if you need support.

 

Cause

Salesforce Platform updated its security controls as of July 2026 to enforce Refresh Token Rotation by default on newly created External Client Apps (ECAs). Because Tableau Server currently does not process rotated single-use refresh tokens for Salesforce / Salesforce Data Cloud connectors, the token endpoint returns 400 Bad Request (invalid_grant: expired access/refresh token) when Tableau Server attempts to use the saved refresh token on subsequent connections.

Resolution

To resolve this issue, disable Refresh Token Rotation on the Salesforce External Client App (ECA) used for the connection:

  1. Log in to your Salesforce Org as an administrator.
  2. Navigate to Setup > External Client Apps > External Client App Manager.
  3. Select your target External Client App, then go to Settings > Edit. Scroll down and click OAuth Settings.
  4. Uncheck Enable Refresh Token Rotation.

Note: Due to recent Salesforce Platform security policy updates, changing this setting directly in Setup may be locked for newly created apps. If the checkbox is greyed out, please contact Salesforce Platform Support to request permission to disable Refresh Token Rotation for the affected External Client App.

Once Refresh Token Rotation is disabled, test connections and extract refresh schedules on Tableau Server will complete successfully without requiring re-authentication.

Knowledge Article Number

005390146

 
Loading
Salesforce Help | Article