Salesforce: "OAuthCodeExchangeError" when connecting

Edited

OAuthCodeExchangeError means the Salesforce sign-in itself went through, but when Apideck exchanged the authorization code for tokens, Salesforce rejected it. Salesforce's own reason isn't passed back in this error, so the fastest way to fix it is to check the settings below. Almost all cases come down to one of them.

Checklist

1. The Environment matches the org

The Salesforce connection in Vault has an Environment setting:

  • Production (the default if left empty) signs in on login.salesforce.com.

  • Sandbox signs in on test.salesforce.com.

Choose and save the environment before clicking Authorize. A sandbox (your username has a sandbox suffix) needs Sandbox. A Developer Edition org isn't a sandbox, so choose Production for it.

2. PKCE is enabled on your Salesforce app

If you use your own Salesforce app (External Client App or Connected App), check its OAuth security settings:

  • Require Proof Key for Code Exchange (PKCE): leave this checked. Apideck always uses PKCE when it connects to Salesforce. If authorization fails with missing required code challenge, this setting is the cause.

3. The callback URL is exactly right

Your Salesforce app's Callback URL must be:

https://unify.apideck.com/vault/callback

(or your own custom Vault domain's callback URL, if you've set one up).

4. The Consumer Key and Secret in Apideck match the app

Copy the Consumer Key and Consumer Secret from your Salesforce app again and paste them into the Salesforce connector settings. Watch out for extra spaces, and for credentials from a different app.

5. Give a new app a few minutes

It can take up to 10 minutes for a new Salesforce app to become active. If authorization fails right after you created or changed the app, wait a few minutes and try again.

Connected, but later failing to refresh?

That's a different setting. If authorization works but the connection later fails to refresh its token:

  • Require secret for Refresh Token Flow should be unchecked.

  • Enable Refresh Token Rotation should be unchecked.

Rotation only affects token refreshes, not the initial connection, so it doesn't cause OAuthCodeExchangeError.

Full setup steps are in the Salesforce configuration guide.

Related

Contact Apideck support through the Customer Portal (the Requests link at the top of this help center), your Slack channel with us, or support@apideck.com with the consumer ID and the time you tried, if none of these fix it.

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.