---
title: "Invalid_grant authentication errors Troubleshoot guide"
canonical: "https://support.appfire.com/space/SUPPORT/3268378662/Invalid_grant%20authentication%20errors%20Troubleshoot%20guide"
format: markdown
---
> Macro (toc)

# Overview

Use this article to resolve the `invalid_grant` error in Connector for Salesforce & Jira. This error is returned by Salesforce when the OAuth authorization is no longer valid, commonly because the integration user credentials changed, the refresh token expired, or Salesforce security settings were updated. Re-authorizing the connection in Jira and refreshing the Salesforce package connection typically restores syncing and record visibility.

## Environment

- **Product:** Connector for Salesforce & Jira
- **Platform:** Jira Cloud
- **Integration:** Salesforce

# Problem

The connection between Salesforce and Jira may stop working, which can prevent users from viewing Salesforce data in Jira issues or prevent synchronization between the two systems. The following error may appear in logs, connection tests, or authorization responses:

`error: invalid_grant`

**Symptoms:**

- The connection status fails or shows an authorization issue in the Jira app settings.
- Salesforce data is not visible on Jira issues.
- Automatic synchronization between Salesforce and Jira fails.

# Cause

The `invalid_grant` error is generated by Salesforce and indicates that the existing OAuth authorization can no longer be used. Common causes include:

- **Expired or revoked refresh token:** The Salesforce OAuth refresh token used by the integration has expired or was revoked.
- **Salesforce security policy changes:** Salesforce security updates or policy changes require the connector authorization to be refreshed.
- **Integration user changes:** The Salesforce integration user’s password changed, the user was deactivated, or the user’s access was restricted.
- **Connected app restrictions:** The Salesforce connected app is not approved or is blocked by IP, profile, or permission restrictions.

# Solution/Workaround

Re-authorize the connection from Jira, then update the Salesforce package connection with a new API access token. Do not uninstall or reinstall the connector, because doing so may remove existing bindings or configuration.

### Step 1: Re-authorize the connection in Jira

1. Log out of Salesforce in the browser, or use an incognito/private browser window, to ensure the correct Salesforce integration user is used during authorization.
2. In Jira, go to **Settings** > **Apps** > **Connector for Salesforce & Jira**.
3. Open the **Connections** page.
4. Locate the affected connection and click **Revoke** or **Revoke access**.
5. Click **Authorize**.
6. When redirected to Salesforce, log in with the dedicated **Salesforce integration user** and approve the authorization request.
7. After the connection is authorized in Jira, open the **More** menu for the connection and select **API access token**.
8. Copy the generated API access token.

### Step 2: Refresh the connection in Salesforce

1. In Salesforce, go to **Setup** > **Installed Packages**.
2. Find the **Jira for Salesforce** package and click **Configure**.
3. Revoke the existing package connection if the option is available.
4. Add or update the connection using the API access token copied from Jira.
5. Click **Save**.
6. If multiple Salesforce package connections exist, confirm that the refreshed connection is set as the default connection.

### Step 3: Verify the Connection

- In Jira, return to the **Connections** page and confirm that the connection status is connected or authorized.
- Open a Jira issue that has an associated Salesforce record and verify that Salesforce data loads correctly.
- Trigger a sync or update an associated Salesforce record, then confirm the Jira issue updates as expected.
- If the error persists, confirm that the Salesforce integration user is active, has the required permissions, and is not blocked by Salesforce login IP ranges or connected app policies.

# Additional Resources

- [How to change the Salesforce integration user](https://support.appfire.com/space/CSFJIRA/2256308548/How+to+change+the+Salesforce+integration+user)
- [Determine the Salesforce integration user](https://support.appfire.com/space/CSFJIRA/3091596904/Determine+the+Salesforce+integration+user)
- [Salesforce Documentation: OAuth 2.0 Authorization Errors](https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_flow_errors.htm&type=5)