Skip to main content

When in my dev hub am trying to link the namespace, then getting the error below. The connected app is disabled by Salesforce; that's why I cannot uncheck the PKCE validation. Tried with tooling api also, did not able to do it. 

 

How to link the namespace? Is there any alternate way? 

 

#Salesforce Developer  #Salesforce Admin

6 Antworten
  1. 18. Aug., 16:23

    Thanks for testing those, Souvik - since browser, My Domain, and admin are all ruled out, that error is almost certainly coming from one specific org-wide setting: 'Require Proof Key for Code Exchange (PKCE) Extension for Supported Authorization Flows' in Setup > OAuth and OpenID Connect Settings. 

     

    Here's the trap: you mentioned enabling PKCE there. When that org-wide toggle is on, the org forces a code_challenge on every supported authorization flow - but the internal namespace-linking flow doesn't send one, so it fails with exactly 'missing required code_challenge'. So that setting being enabled is what's breaking the link, not something you're missing. 

     

    The fix: turn that setting off (Setup > OAuth and OpenID Connect Settings) in the org that owns the namespace - and in the Dev Hub too if it's enabled there - then retry the namespace link. Once it's linked, you can switch it back on if you want PKCE enforced for your own apps. Note this org-wide toggle is separate from the greyed-out PKCE box on the Salesforce-managed connected app you can't edit - this one you do control. 

     

    If it's already off and still fails, then it's on Salesforce's side (the managed linking app), and the right path is a Partner Support case referencing the error - it's a managed flow you can't patch yourself. But I'd bet on the org-wide setting; toggle it off and the link should go through. 

     

    Hope that finally clears it! 

     

    And if this resolves it, please mark it as the Best Answer so it helps the next person who hits this - thanks! 🙂

0/9000