---
title: "Breaking changes Connector for Salesforce & Jira 2.1.19-jira-10"
canonical: "https://support.appfire.com/space/477986818/3227713606/Breaking%20changes%20Connector%20for%20Salesforce%20%26%20Jira%202.1.19-jira-10"
format: markdown
---
**Release date**: 5/8/2026

Salesforce is enforcing new OAuth security requirements effective **May 11, 2026**. As part of this change, Device Flow authentication is no longer supported, and Web Flow is now the only way to authenticate the Connector for Salesforce and Jira DC connection. Web Flow relies on the External Client App, which now requires new security controls to be enabled. **Most admins will need to reauthenticate their connection.** Failure to act will break all automated workflows and data syncs between Salesforce and Jira.

**Jira compatibility**:** **Jira Data Center 10.0.0 - 10.7.4

---

## Overview

To keep Connector for Salesforce and Jira DC working after May 11, 2026, you must make sure your Salesforce External Client App meets new requirements. Salesforce is mandating new OAuth security controls: PKCE, Refresh Token Rotation, and Refresh Token TTL.

## What you need to do

### Update to the newest version

1. Update the **Connector for Salesforce & Jira** app in Jira to the latest version (at least 2.1.19-jira-10) available on the [Marketplace](https://marketplace.atlassian.com/apps/1214214/connector-for-salesforce-jira/version-history).

### Check if the External Client App is configured 

1. In Salesforce, click **Settings **() > **Setup**.
2. In the **Quick Find** box, enter *App Manager*, and select **External Client** **App Manager**.
3. Check if you have enabled the External Client App for Connector for Salesforce & Jira DC in Salesforce.

![External Client App Manager](media://170891f9-9297-447b-b07c-ce566543e713)

### **If you don’t have the External Client App set**

You need to revoke and then reauthenticate your connection in Jira.

1. In Jira, go to **Salesforce** > **Connections** from the top navigation bar
2. Select the impacted connection, and click **Revoke Access**.
3. Reauthenticate your connection by configuring External Client App Manager.  
For detailed instructions, see [Authorize the connection](https://support.appfire.com/space/477986818/2560820073/Set+up+a+connection+to+Salesforce#Step-3:-Authorize-the-connection).

### If you **have the External Client App set**

Update the security and policy settings

1. Enable required security controls: PKCE, Refresh Token Rotation, and Refresh Token TTL.
2. Update the App Authorization policies for refresh token.

For detailed instructions, see [Configure External Client App Manager](https://support.appfire.com/space/477986818/2560820073/Set+up+a+connection+to+Salesforce#Configure-External-Client-App-Manager).

---

> 📝 As part of this security update, Salesforce refresh tokens will expire after a maximum of 30 days of inactivity. If your connection goes unused for 30 days, you'll need to reauthorize it. For more details, see [Revoke access for expired connection](https://support.appfire.com/space/477986818/3227582508).

---

---