5 Salesforce deadlines between now and summer 2027 that could break your integrations
Integrations that rely on older login methods could stop working within weeks, while new tools for governing AI agents arrive
Salesforce customers have a little under a month to prepare for the first enforcement deadline in the company's Winter '27 release. Starting November 4, 2026, refresh tokens in production orgs will expire after 30 days of inactivity. Integrations that run infrequently, and assume their credentials stay valid indefinitely, could fail without warning.
That change opens a release that, according to a Salesforce architecture blog post published October 5 by Principal Architect Evangelist Marlene Guerra-Reeve, retires legacy capabilities and adds new features for scaling AI agents. The post groups the changes into four areas: security, capacity, agent architecture, and governance.
Older logins on the way out
More enforcement dates follow the November token change. Salesforce will restrict the OAuth 2.0 device flow from November 30, 2026. The username-password, user-agent, and hybrid user-agent flows retire on February 20, 2027.
The post tells administrators to inventory every integration and its authentication method, and to move to the most secure option each system supports. It warns against switching to another method that is itself heading for restriction.
Two more retirements arrive with the Spring '27 release. Salesforce to Salesforce will stop working entirely, and the Salesforce Connect cross-org adapter must move to named credentials. Support for connected apps ends by Summer '27. Salesforce wants customers to migrate to External Client Apps, which are closed by default and separate application settings from administrative policy.
More room to work with
Some limits are loosening. Synchronous Apex heap size rises from 6 MB to 10 MB, and the asynchronous limit goes from 12 MB to 25 MB. Elastic Async Apex Jobs, still in beta, now covers batch jobs as well as future methods and Queueable jobs. Extra capacity is capped at the customer's licensed async job limit or 2 million jobs, whichever is lower.
Salesforce is also adding Flow features, including record-lock retry and loop-free filtering, and a sharing setting that keeps manual shares when a record changes owner. The post suggests teams review custom Apex and automation built to get around these limits, since some of it may now be unnecessary. It also advises checking that retained shares fit an organization's access rules before turning the setting on.
Building for agents
The release also leans heavily on Agentforce, Salesforce's AI agent platform. Multi-Agent Orchestration, which lets specialist agents work together and hand off across channels such as WhatsApp and mobile, became generally available in August 2026.
Other additions include an API Catalog for registering the Model Context Protocol (MCP) servers and APIs that agents may call. Data 360 can now resolve parent-child record hierarchies, including zero-copy data from BigQuery, Databricks, and Snowflake. For developers, SLDS AI Skills and ApexGuru aim to keep AI-generated code consistent and reviewable. The post argues that agent design choices are easier to make before agents go into production than to fix afterward.
New oversight tools, with caveats
On governance, Salesforce is offering Security Health Review, which replaces the one-time Health Check PDF with continuous findings and an audit trail. It is limited to Signature Success Plan customers. Scale Center sends org-health alerts to Slack, but availability depends on edition and support plan, and it is not supported in Government Cloud Plus.
Two Security Center additions arrived in mid-September. MCP Server Monitoring, in beta, shows risk scores and configuration changes for connected servers. Security Mesh pulls security data from Salesforce and outside sources into one place, though it requires Security Center, Data 360, and supporting licenses. The post says the MCP risk score should inform reviews, not stand in for an approval decision.
What to do now
Guerra-Reeve advises customers to deal with the deadline-driven security work first, then decide which new features justify the cost compared with existing tools. She also recommends keeping an architectural decision record for each choice.