Preparing for Salesforce Connected App Usage Restrictions
Overview
Salesforce has announced changes to how uninstalled connected apps function in customer orgs, effective September 2025. These changes impact AutoRABIT products that connect to your Salesforce environments using the OAuth 2.0 Client Credentials Flow.
What’s Changing in Salesforce
Uninstalled connected apps restricted — New authorizations will be blocked unless specific permissions are granted.
OAuth 2.0 Device Flow blocked — Not used by AutoRABIT.
New permissions introduced:
Approve Uninstalled Connected Apps
Use Any API Client
Impact on AutoRABIT Products
Vault, ARM, and CodeScan Cloud connect to Salesforce via Client Credentials Flow, which creates an uninstalled connected app.
Existing connections (before September 2025): Will continue to work.
New connections (after September 2025): May fail unless permissions are updated by your Salesforce admin.
Actions Required
Identify AutoRABIT Connected Apps:
Go to Setup → Connected Apps OAuth Usage in Salesforce.
Locate entries linked to AutoRABIT.
Update User Permissions:
If API Access Control is enabled: Assign “Use Any API Client.”
If API Access Control is not enabled: Assign either “Approve Uninstalled Connected Apps” or “Use Any API Client.”
Grant these permissions only to trusted integration users.
Plan for Future Stability:
AutoRABIT is preparing enhancements to support installed connected apps for long-term compliance.
Best Practices
Use a dedicated integration user for AutoRABIT.
Grant only minimum required permissions.
Review unused connected apps regularly and remove them.
Need Help?
Contact AutoRABIT Support ([email protected]).
Refer to Salesforce’s announcement: Prepare for Connected App Usage Restrictions Change.
Additional Resources
Refer to the Salesforce documentation below for additional details.
Last updated
Was this helpful?