Salesforce Connection Security Requirements

Prev Next

Overview

Salesforce requires all AgentExchange (formerly AppExchange) partner apps — including the HG Insights connected app — to implement four OAuth security controls. HG Insights enabled all four on August 26, 2026.

You don't need to do anything. These controls live entirely in HG Insights' Salesforce connected app configuration. Your existing connection keeps working, and there are no setup steps on your side.

The four controls

Control What it does
PKCE (Proof Key for Code Exchange) Protects the OAuth login flow against authorization-code interception.
Refresh Token Rotation (RTR) Issues a new refresh token each time HG Insights renews access, invalidating the old one.
Idle Refresh Token TTL — 30 days If HG Insights doesn't use a refresh token for 30 days, it expires and reconnection is required.
Refresh Token IP Allowlist Refresh requests are restricted to HG Insights' known server IP ranges.

What you might notice

  • Reconnect prompt after a long period of inactivity. If a Salesforce integration goes unused for 30+ days, the connection will expire per the new TTL and need to be reauthorized. See Connecting or Updating the Salesforce Connection.
  • "PKCE verifier expired. Please reconnect Salesforce" during OAuth authorization. This means the login flow took too long to complete. Refresh the page and redo the OAuth flow promptly. See Troubleshooting: Salesforce Connector Connection Issues.
  • Connection drops shortly after reconnecting, if your org enforces Salesforce Login IP Ranges. Your Salesforce admin needs to set IP Relaxation to "Relax IP restrictions" on the HG Insights connected app. See Connecting Salesforce Without Admin Privileges for where that setting lives.

Related articles