To improve security and help protect your Salesforce data from unauthorized access, set
an IP range to allow refresh tokens. When you turn on Enforce Refresh Token IP Allowlist, only IPs
in allowed ranges can complete the OAuth web server flow or the refresh token flow.
Required Editions
Available in: Lightning Experience
Available in: Professional, Performance, Unlimited, and
Developer Editions
Note IP allowlist ranges support both IPv4 and IPv6.
Refresh Token IP
Allowlists differ from Trusted IP Ranges in a few ways. Trusted IP ranges require verification
of requests from IP addresses outside the trusted range. The IP allowlist for refresh tokens
completely blocks requests that come form outside the allowed ranges. Also, trusted IP ranges
affect device activation and might not trigger activation even if the request comes from a
trusted IP address. Refresh token IP allowlists have no affect on device activation requests, so
device activation will be triggered as long as the request comes from an allowed IP address.
Configure IP range allowlists for refresh tokens. You can create up to 128 IP address
ranges, with no more than 256 IP addresses total.
From Setup, in the Quick Find box, enter External Client
Apps Manager, and then select External Client Apps
Manager.
From the actions list for the external client app, select Edit
Settings.
Turn on Enforce Refresh Token IP Allowlist.
In the Refresh Token IP Allowlist section, click Add.
For the start IP address, enter a valid IP address. For the end IP address, enter the same
or higher IP address.
Enter multiple, discontinuous ranges by clicking Add.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.