TICKET HX-1267

Salesforce integration keeps disconnecting

Status: Resolved Category: Integrations Priority: P2 Customer: Aisha Bhatt (Coastline Realty) Agent: Sandra Liu
Aisha Bhatt Customer 2024-03-29 10:15 UTC

Our Salesforce connection has 'expired' three times this month. Every time I reconnect and it works for a week or two then breaks again. This is killing our pipeline.

Sandra Liu Helix Support 2024-03-29 10:34 UTC

Hi Aisha — that's frustrating. Repeated OAuth disconnects almost always trace to one of these: (1) the Salesforce user who authorized has expiring credentials in SF (password expiry, MFA challenge changes), (2) Salesforce admin policy is revoking long-lived OAuth grants, or (3) the user account is being deactivated and reactivated.

Who is the SF user that authorized the connection — is it a personal account or a service account?

Aisha Bhatt Customer 2024-03-29 10:42 UTC

It's connected as me (the SF admin). Personal account.

Sandra Liu Helix Support 2024-03-29 10:51 UTC

Found it. Your Salesforce org has a 'Refresh token policy' set to expire on first use. That means every time we use the refresh token to get a new access token, the refresh token itself is invalidated. This basically makes the connection one-shot — works until the access token expires, then dead.

Two paths:

  1. Change the refresh token policy in your SF Connected App settings to refresh until revoked. This is the standard setting for integrations.
  2. Switch to a service account specifically for Helix. Best practice for integrations anyway — survives admin role changes, separates audit trails.

I'd recommend doing both, but option 1 alone fixes the immediate problem.

Aisha Bhatt Customer 2024-03-29 11:10 UTC

Updated the refresh token policy. Reconnecting now.

Aisha Bhatt Customer 2024-04-12 09:22 UTC

Two weeks in, no disconnects. Looks like that did it. Will move to a service account when I have time. Thanks.

RESOLUTION

Customer's Salesforce connected app refresh token policy was set to 'expire on first use,' which invalidated the refresh token every time Helix rotated access tokens. Changed policy to 'refresh until revoked.' Recommended switching to a service account long-term. Stable for 2+ weeks after fix.