Connected Apps.
All posts.
The Salesforce Data Theft Campaigns, 2025 to 2026: A Verified Timeline and the Audit That Covers All of Them
Four campaigns, three ways in, none a platform bug. The dates and actor names checked against primary sources, plus the audit that covers all three routes.
Salesforce Restricts the OAuth Device Flow on 30 November 2026: Your Connected App Has to Become an External Client App
From 30 November 2026 the OAuth device flow works only from local external client apps. Connected apps that use it must migrate or stop authenticating.
Salesforce Retires the OAuth User-Agent Flows on 20 February 2027: Move to Web-Server Flow with PKCE
The OAuth user-agent and hybrid user-agent flows retire on 20 February 2027. What breaks, why a token in the URL is the problem, and where to move next.
Migrating Connected Apps to External Client Apps: The Tool Now Covers Packaged and Distributed Apps
Connected apps end in Summer '27. The migration tool now covers packaged and distributed apps, and keeps existing tokens and sessions valid through it.
Which of Your Salesforce Connected Apps Use Less Than They're Granted? Ask Your Own Logs
Static scanners tell you what a connected app was granted, not what it uses. Here is how to measure the over-grant per object from your own EventLogFile.