Blog

Announcement: Salesforce External Client App is now Available

Author

  • Angel_Tawade

    SailPoint

Following our initial advisory, this second announcement confirms that the SailPoint External Client App (ECA) package is now live on Salesforce AgentExchange. The ECA is now the only supported authentication method for the ISC Salesforce connector(VA and SaaS). The 90-day migration window opens July 1, 2026 use the time between now and then to install the ECA package, align your team, and validate in sandbox (available June 24)

Note : Salesforce Activity Data Insights (ADI) connector, Now also support ECA Authentication

Why is this happening?

Salesforce is retiring its Connected App framework for external integrations and requires migration to External Client Apps (ECA). This is a Salesforce platform change, not a SailPoint product update. SailPoint has updated the ISC Salesforce connector to comply and published the ECA package on AgentExchange. You must complete migration by September 30, 2026 to maintain connectivity.

Key Dates

Plan your migration around these dates. Use the sandbox first to validate before production goes live.

MilestoneDate

Sandbox availability

June 24, 2026

Production availability

June 29, 2026

Migration window opens

July 1, 2026

Migration window closes

September 30, 2026

Legacy auth permanently removed

October 1, 2026

Deadline: September 30, 2026. After this date, Basic Auth and all OAuth 2.0 Connected App flows (JWT, Refresh Token, Client Credentials) are permanently removed. Connectors not migrated will lose Salesforce connectivity provisioning, aggregation, and all connector operations will fail.

What You Need to Do?

Install the SailPoint ECA package from Salesforce Agent Exchange and reconfigure your connector with ECA Authentication before September 30, 2026 ; connectors using deprecated authentication methods will stop working after that date.

What Is Changing?

Salesforce is replacing Connected Apps with External Client Apps for all external API integrations. The table below shows exactly what changes in the ISC Salesforce connector(VA and SaaS)

AreaBefore (Deprecated)After (Required)

Auth Framework

Salesforce Connected App

Salesforce External Client App (ECA)

OAuth Flow

JWT / Refresh Token / Client Credentials / Basic

OAuth 2.0 Authorization Code Grant only

Deprecated Authentication Methods

The following methods are deprecated as of July 01, 2026. They remain accessible via the backward compatibility toggle during the 90-day window. All deprecated methods and the legacy Connection Settings UI will be permanently removed on September 30, 2026.

MethodStatusAction Required By

Basic Authentication

Deprecated

September 30, 2026

OAuth 2.0 - JWT Bearer

Deprecated

September 30, 2026

OAuth 2.0 - Refresh Token

Deprecated

September 30, 2026

OAuth 2.0 - Client Credentials

Deprecated

September 30, 2026

External Client App (ECA)

Supported — New Default

—

Note: The backward compatibility toggle allows temporary reversion to a deprecated method if you encounter issues during migration. This toggle will be removed when the deprecation window closes and the deprecated connection settings UI will no longer be available.

Migration Steps

Complete all three steps by September 30, 2026

Step 1 - Install the External Client App Managed Package from Salesforce AgentExchange

  1. Go to the Salesforce AgentExchange.
  2. Search for the SailPoint ECA-SailPoint Identity Security for Salesforce
  3. Enter your Salesforce credentials to authorize the installation.
  4. Select Install for All Users (or your preferred security level) within your Salesforce organization.

Step 2 - Configure ECA Authentication in the ISC Salesforce Connector

In the Identity Security Cloud UI, open the Salesforce connector and go to the ECA Authentication section.

  1. Turn on the Enable External Client App (ECA) toggle.
  2. Under Client Configuration, add the following key-value pair:
    1. Key: host_name
    2. Value: Token URL for your environment — test.salesforce.com (sandbox) or login.salesforce.com (production), depending on your Salesforce tenant configuration
  3. Click on Authorize and complete the OAuth 2.0 Authorization Code Grant flow.
  4. Select Save.
  5. Review the configuration and select Test Connection to verify the integration.
Note: The service account used to authorize the ECA must have adequate permissions to manage the required Salesforce objects.

Step 3 - Validate and Move to production

  1. Run a test aggregation to confirm accounts and entitlements are returned correctly.
  2. Validate provisioning operations (create, update, disable) against a test account.
  3. Confirm lifecycle events are flowing as expected.
  4. Once validated, move to production

Important Considerations for ECA Authentication

  1. Maximum Concurrent Tokens

Salesforce limits active refresh tokens to five per user per External Client App. If a sixth connection is requested, Salesforce automatically and silently revokes the oldest active token. No warning is issued

  1. Revoked Token Reuse - Critical Risk

If an authenticated source attempts to authenticate using a previously revoked token (such as the silently dropped oldest token), Salesforce treats the attempt as a critical security threat. As a result, Salesforce immediately invalidates all active refresh tokens and sessions for that user across all clients.
Important: If this occurs, you must reauthorize the integration to continue. To avoid this scenario, ensure that no more than five concurrent authenticated connections are active per user for a given ECA.

  1. Backward Compatibility Toggle

A backward compatibility toggle is available in the connector UI during the 90-day deprecation window. This allows you to temporarily revert to a previously working legacy configuration if issues arise during migration. This toggle will be permanently removed when the window closes and will not be available post-deprecation.

Action Checklist

The migration window opens July 1, 2026. Start preparing now to avoid last-minute rush.

  1. Share this announcement with your Salesforce admin and identity governance team today.
  2. Align internally on ECA setup, AgentExchange installation approval, and test scheduling.
  3. Start in sandbox (available June 24) install the ECA package and validate before production goes live.
  4. Install the ECA package from Salesforce AgentExchange before July 1, 2026.
  5. Configure the connector with the correct host_name for each environment (sandbox and production).
  6. Complete validation in non-prod before promoting to production (available June 29).
  7. Use the backward compatibility toggle only as a temporary fallback not a substitute for migration.
  8. Contact your SailPoint PM or Customer Success Manager for migration support
    Deadline: September 30, 2026,

After this date, legacy authentication is permanently removed. Connectors not migrated will lose Salesforce connectivity provisioning, aggregation, and all connector operations will fail.

Support and Resources

  • Contact your SailPoint Product Manager or Customer Success Manager for migration support.

To ask questions and learn more please visit the Developer Community.