Upcoming Security Enhancements for Salesforce Integrations (PKCE & Refresh Token Rotation)

Christian Delorey
Christian Delorey

To continue providing a secure and reliable Salesforce integration, Riva will be implementing enhancements to our cloud platform that align with Salesforce's updated authentication security requirements.

These enhancements include support for modern OAuth security features, including:

  • Proof Key for Code Exchange (PKCE)
  • Refresh Token Rotation (RTR)

Salesforce has announced that these security controls will be enforced for partner applications beginning August 24, 2026. To ensure continued compatibility, Riva will complete the required platform updates before this deadline.

What does this mean?

Riva will deploy these security enhancements to all Riva Cloud environments as part of a planned rollout.

No action is required from customers or end users. However, each environment will undergo a scheduled maintenance window to complete the transition.

Scheduled Maintenance Windows

The rollout will occur according to the following schedule:

ProductMaintenance DateMaintenance Window
Riva InsightJuly 31, 20268:00 PM – 10:00 PM EST
Riva SyncAugust 14, 20268:00 PM – 10:00 PM EST

The expected service interruption for each environment is approximately 20 minutes, although the full maintenance window has been reserved to allow sufficient time to complete the deployment.

Frequently Asked Questions

Why is Riva making this change?

Salesforce has introduced enhanced authentication security requirements for connected applications. These improvements strengthen OAuth security and help protect customer environments. Riva is implementing these enhancements to remain fully compatible with Salesforce's security standards.

Do I need to do anything?

No. These updates will be completed by the Riva Cloud Operations team as part of our managed cloud service.

Will there be downtime?

Yes. Each environment will have a scheduled maintenance window while these changes are being implemented. The expected interruption is approximately 20 minutes.

Will users need to re-authenticate?

No. Users are not expected to re-authenticate their Salesforce connections following the upgrade.

Questions?

If you have any questions regarding this maintenance or its impact, please contact Riva Technical Support.