Skip to main content

   

Subject: Link Namespace fails: invalid_request "missing required code challenge" 

    

   Dev Hub org ID: <xyz>. Namespace org ID: <abc>. Namespace: Nativesign. 

   Namespace Registries > Link Namespace popup returns error=invalid_request&error_description=missing required code challenge. 

   The connected app "SalesforceDX Namespace Registry" has PKCE checked and locked ("contact Support"). Org-level PKCE is OFF. How can I link my namespace? 

 

#Package Manager  #Appexchage Apps  #Generation Managed Package  #Installed Packages

1 Antwort
  1. Heute 13:54

    This looks like a mismatch created by Salesforce's own PKCE enforcement rollout rather than something wrong in your org's configuration. The SalesforceDX Namespace Registry connected app is a Salesforce-owned system connected app used by the Namespace Registries Link Namespace flow, and its PKCE requirement is locked because Salesforce has been moving connected apps and External Client Apps toward mandatory PKCE, with no admin opt-out on system apps like this one. Your org-level Require PKCE toggle being off is not relevant here, since that setting only affects apps that inherit the org default, and this one has its own requirement baked in. 

     

    The "invalid_request / missing required code challenge" error means the client side of this OAuth exchange, the Link Namespace popup itself, is not sending a code_challenge parameter even though the connected app now demands one. Since that popup is Salesforce's own UI and not something you control from Setup, you cannot fix this from your Dev Hub or Namespace org settings. Other admins have hit the same "missing required code challenge" wall on various Salesforce-owned OAuth flows since PKCE enforcement tightened, so this is worth logging as a Salesforce Support case, quoting the exact error and the Dev Hub and Namespace org IDs, so they can confirm whether it is a tracked regression tied to the PKCE rollout on that specific connected app. 

     

    Background on PKCE enforcement:

    https://help.salesforce.com/s/articleView?id=005316703&language=en_US&type=1

     

     

    Assumption: I cannot reproduce your Dev Hub, so I cannot fully confirm this is a Salesforce-side defect versus something specific to your org's Namespace Registry setup. This is inferred from the well-documented PKCE enforcement pattern and other reports of the same error on Salesforce-managed connected apps once PKCE became mandatory without an opt-out.

0/9000