---
title: "OAuth error after enabling PKCE on Salesforce External App"
canonical: "https://support.appfire.com/space/477986818/3256680545/OAuth%20error%20after%20enabling%20PKCE%20on%20Salesforce%20External%20App"
format: markdown
---
## Symptom

After enabling PKCE (Proof Key for Code Exchange) on the Salesforce External App, users see a Salesforce **OAuth Error** message:

*We can't authorize you because of an OAuth error. For more information, contact your Salesforce administrator.*

`OAUTH_APPROVAL_ERROR_GENERIC : `*An unexpected error has occurred during authentication. Please try again.*

The error disables setting up new connections and revoking existing connections. 

## Before you start

Make sure you have:

- Administrator rights in Jira - only administrators can revoke the connection.

## Cause

This error occurs when PKCE is enabled in the Salesforce External App, but the installed version of the Connector for Salesforce & Jira doesn't support the PKCE flow. 

Once PKCE is enabled on an External App, you cannot disable it. The only way to resolve the issue is to install the latest app version.

## Resolution

Download the Connector for Salesforce & Jira DC plugin to a version that supports PKCE from [Marketplace](https://marketplace.atlassian.com/apps/1214214/connector-for-salesforce-jira/version-history):

- For Jira 9: Update to version **2.1.19-jira-9** or later.
- For Jira 10: Update to version **2.1.19-jira-10** or later.

After installing the latest version, retry setting up the connection or reauthorizing. For details, see instructions here [Set up a connection to Salesforce](https://support.appfire.com/space/477986818/2560820073).