API · SDK · runtime · authentication lifecycle intelligence

Last updated · 3 October 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-274 · Authentication & identity

Salesforce retires the username-password OAuth flow for connected apps

Salesforce schedules retirement of the username-password OAuth flow for connected apps on 20 February 2027 and directs integrations to supported replacement flows.

SalesforceOAuthusername-password flowconnected appsretirement

Previous state

Connected apps could authenticate through the username-password OAuth flow.

Current state

From 20 February 2027 the named flow is retired; Salesforce documents web server with PKCE and client credentials as replacement patterns.

Who needs to care

Salesforce connected-app integrations using the username-password OAuth flow.

What to do

Migrate to a supported OAuth flow and validate permissions and token handling before 20 February 2027.

What the source does not prove

The source publication date is not asserted because it is absent from the reconciled authority; the record preserves the stated enforcement date and flow boundary.

Lifecycle history

Dated event sequence

  1. Flow retires

    Salesforce retires the username-password OAuth flow for connected apps.

Evidence ledger

First-party sources

  1. 01
    Salesforce Help — Retirement of the username-password OAuth flow

    Official Salesforce release-note authority · 2027-02-20

    Open official source ↗