Salesforce has introduced updated security requirements for applicable AgentExchange / ISV partner applications that use Salesforce OAuth. These requirements are intended to strengthen OAuth security and help protect mutual customers from unauthorized access or token misuse.
Riva has implemented support for the Salesforce requirements related to Proof Key for Code Exchange and Refresh Token Rotation across the affected Riva product areas, including Riva Sync, Riva Insight, and Riva Sales Engagement.
What Salesforce Requires
Salesforce’s updated requirements include several security controls for applicable Connected Apps and External Client Apps. Two of the key OAuth-related controls are:
- Proof Key for Code Exchange (PKCE)
PKCE helps protect OAuth authorization flows by reducing the risk of authorization code interception. - Refresh Token Rotation
Refresh Token Rotation improves token security by replacing refresh tokens during the OAuth token renewal process and invalidating previously issued refresh tokens.
These controls are part of Salesforce’s broader effort to improve OAuth security for partner applications and reduce the risk of service disruption for customers.
Riva PKCE Support
Riva has updated its Salesforce OAuth connection flows to support PKCE.
This applies to Salesforce OAuth flows used when creating a new connection and when revalidating an existing connection. During the OAuth process, Riva now includes the required PKCE parameter in the initial Salesforce authorization request and uses the corresponding value again during the token exchange.
The PKCE update is backwards compatible. This means Riva can support the updated OAuth flow while continuing to work with Salesforce configurations that have not yet enforced PKCE.
Riva Refresh Token Rotation Support
Riva has also implemented support for Salesforce Refresh Token Rotation.
With Refresh Token Rotation, Salesforce can issue a new refresh token during the token renewal process and invalidate the previously used token. Riva has updated the relevant OAuth handling to support this behaviour so that Riva integrations can continue operating when Refresh Token Rotation is enabled in Salesforce.
Similar to PKCE, Riva’s Refresh Token Rotation support is designed to work with Salesforce configurations where enforcement has not yet been enabled.
Refresh Token IP Allow List Considerations
Salesforce also includes a Refresh Token IP Allow List control for applicable Connected Apps and External Client Apps. This setting restricts refresh token requests to approved IP ranges.
Riva has tested this behaviour with Salesforce OAuth flows using external Connected Apps. Testing confirmed that when Refresh Token IP Allow List enforcement is enabled, refresh token requests may be blocked unless the applicable IP address is included in the Connected App’s allow list.
Testing also showed that Salesforce org-level security settings may affect the authentication flow. In some configurations, additional Salesforce IP range settings may be required before the OAuth flow can complete successfully.
Refresh Token IP Allow List enforcement depends on Salesforce configuration and trusted IP range management. Customers should review the applicable Salesforce requirements before enabling this setting.
Product Areas Impacted
The Salesforce security requirements apply to:
- Riva Sync
- Riva Insight
- Riva Sales Engagement
Riva has completed the required implementation work to support PKCE and Refresh Token Rotation for the affected product areas.
Deployment and Rollout
Riva has implemented support for PKCE and Refresh Token Rotation across the affected Salesforce OAuth flows used by Riva Sync, Riva Insight, and Riva Sales Engagement.
Both updates are designed to support Salesforce’s updated OAuth security requirements while remaining compatible with Salesforce configurations where enforcement has not yet been enabled.
Customer Impact
Riva’s PKCE and Refresh Token Rotation implementations are designed to support Salesforce’s updated OAuth security requirements while remaining compatible with configurations where enforcement has not yet been enabled.
No customer action is required solely because Riva has implemented these updates. Customers planning to enable, enforce, or lock Salesforce security controls should review the applicable Salesforce requirements and Riva release guidance before proceeding.
Salesforce notes that certain security controls must be confirmed and locked as part of its compliance process, and that locked controls cannot be unlocked.