When connecting Tableau Server to Salesforce or Salesforce Data Cloud using a newly created External Client App (ECA) where Refresh Token Rotation is enabled by default, OAuth authentication succeeds on the initial connection attempt but consistently fails on all subsequent attempts.
As a result, users encounter a Data Source Error across multiple scenarios:
Example Error Message:
Data Source Error
Unable to proceed because of an error from the data source.
Tableau has detected that the OAuth refresh token has expired. Please re-authenticate using new credentials. Contact your Tableau administrator if you need support.
Salesforce Platform updated its security controls as of July 2026 to enforce Refresh Token Rotation by default on newly created External Client Apps (ECAs). Because Tableau Server currently does not process rotated single-use refresh tokens for Salesforce / Salesforce Data Cloud connectors, the token endpoint returns 400 Bad Request (invalid_grant: expired access/refresh token) when Tableau Server attempts to use the saved refresh token on subsequent connections.
To resolve this issue, disable Refresh Token Rotation on the Salesforce External Client App (ECA) used for the connection:
Note: Due to recent Salesforce Platform security policy updates, changing this setting directly in Setup may be locked for newly created apps. If the checkbox is greyed out, please contact Salesforce Platform Support to request permission to disable Refresh Token Rotation for the affected External Client App.
Once Refresh Token Rotation is disabled, test connections and extract refresh schedules on Tableau Server will complete successfully without requiring re-authentication.
005390146

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.