Loading
Prepare for Email to Become the Default Login ExperienceRead More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Identify Your Users and Manage Access
Migrate a Distributed Connected App to an External Client App

Migrate a Distributed Connected App to an External Client App

Use the automated process to create an external client app that replaces an existing connected app that is used on other orgs. After migration, the new external client app can be packaged and distributed to other orgs through App Exchange. The old connected app remains as a read-only version in App Manager. External client apps created through migration are secure.

Required Editions

Available in: Lightning Experience
Available in: Professional, Performance, Unlimited, and Developer Editions
User Permissions Needed
To create local External Client Apps Create, edit, and delete External Client Apps
Tip
Tip Instead of completing this task manually, get help from Setup with Agentforce. For example, tell the Setup agent, “Migrate the Acme connected app to an external client app.” For more information, see Identity Management in Setup with Agentforce.

Distributed connected apps can exist in three scenarios.

  • Packaged connected apps
  • Unpackaged connected apps that are installed on external orgs
  • Unpackaged connected apps that are installed on orgs that the app developer controls

Migrate a Packaged Connected App

Migrate a connected app that is packaged in a first-generation managed package or a second-generation managed package.

  1. From Setup, in the Quick Find box, enter App Manager, and then select App Manager.
  2. Open the connected app by clicking the name.
    If the connected app is eligible for migration, the Migrate to External Client App button is available.
  3. Click Migrate to External Client App.
  4. Confirm that the connected app doesn’t use the username-password flow and indicate that the connected app is used on multiple orgs.
  5. Click Migrate.
    A window opens with a link to the new external client app. The distribution state for the external client app is Packaged.
  6. Create a new package version containing the external client app.

After you create and package the external client app, distribute it to subscriber orgs. When the new package version is installed, the system looks up the existing connected app by consumer ID. If the connected app is found, its policies are migrated to the new external client app. Existing integrations continue to work without interruption.

Migrate an Unpackaged Connected App

Migrate a connected app that was created in an org and used on other, external orgs without formal package distribution.

  1. From Setup, in the Quick Find box, enter App Manager, and then select App Manager.
  2. Open the connected app by clicking the name.
    If the connected app is eligible for migration, the Migrate to External Client App button is available.
  3. Click Migrate to External Client App.
  4. Confirm that the connected app doesn’t use the username-password flow.
  5. Click Migrate.
    A window opens with a link to the new external client app. The distribution state for the external client app is Packaged.
  6. Package the external client app in a 1GP or 2GP managed package.
  7. Publish the package to App Exchange.

When subscribers install the packaged external client app, the system looks up the existing connected app by consumer ID. If the connected app is found, its policies are migrated to the external client app. Existing integrations continue to work without interruption.

Migrate a Connected App Distributed Across Internal Orgs

Migrate a connected app that was created in an org and used on multiple internal orgs.

  1. From Setup, in the Quick Find box, enter App Manager, and then select App Manager.
  2. Open the connected app by clicking the name.
    If the connected app is eligible for migration, the Migrate to External Client App button is available.
  3. Click Migrate to External Client App.
  4. Confirm that the connected app doesn’t use the username-password flow.
  5. Click Migrate.
    A window opens with a link to the new external client app. The distribution state for the external client app is Packaged.
  6. Package the external client app in an unlocked 2GP managed package.
  7. Distribute the package to the other internal orgs.

When the internal org installs the packaged external client app, the system looks up the existing connected app by consumer ID. If the connected app is found, its policies are migrated to the new external client app. Existing integrations continue to work without interruption.

 
Loading
Salesforce Help | Article