Skip to main content

#Appexchage Apps18 人がディスカッション中

Hi everyone,

We are preparing an external API / web application integration for our AppExchange Security Review. The review team will need to test our API endpoints from their automated scanning suites and dynamic networks.

Our main operational blocker right now is MFA and Device Activation (OTP). Because our team does not have personnel available on standby 24/7 to instantly provide multi-factor authentication access codes or email OTP tokens to the reviewers, we need an entirely hands-off authentication architecture for our test environment.

Given Salesforce’s strict platform enforcements restricting traditional UI MFA bypass permissions, what is the current accepted practice for API apps?

My Questions:

  • If we provision a dedicated Salesforce Integration User license (which uses API-only tokens/OAuth instead of interactive UI login), does the Security Review team's automated testing suite natively support this without triggering an MFA or Device Activation challenge?
  • If the review suite requires standard user credentials that trigger an unexpected email OTP, how are partners managing this asynchronously without a 24/7 live operations team to hand over codes?

We want to make sure we architect our authentication flow correctly so that the submission doesn't fail pre-queue validation due to a missed MFA prompt. Any advice from recent submitters would be huge. 

 

#Appexchage Apps

 

 

#Security Review  #Agentforce

1 件の回答
  1. 9月22日 5:44

    For an AppExchange Security Review, I’d avoid designing around the assumption that an API-only user automatically bypasses every authentication control. The safer approach is to confirm the current review-team requirements for integration credentials and test the exact OAuth/API flow in the submitted environment beforehand. If automated scanners require interactive authentication, Salesforce Partner Support or the Security Review team should clarify the supported testing arrangement rather than relying on manual OTP handling.  Visit here for more information.

0/9000

   

Subject: Link Namespace fails: invalid_request "missing required code challenge" 

    

   Dev Hub org ID: <xyz>. Namespace org ID: <abc>. Namespace: Nativesign. 

   Namespace Registries > Link Namespace popup returns error=invalid_request&error_description=missing required code challenge. 

   The connected app "SalesforceDX Namespace Registry" has PKCE checked and locked ("contact Support"). Org-level PKCE is OFF. How can I link my namespace? 

 

#Package Manager  #Appexchage Apps  #Generation Managed Package  #Installed Packages

1 件の回答
  1. 9月21日 13:54

    This looks like a mismatch created by Salesforce's own PKCE enforcement rollout rather than something wrong in your org's configuration. The SalesforceDX Namespace Registry connected app is a Salesforce-owned system connected app used by the Namespace Registries Link Namespace flow, and its PKCE requirement is locked because Salesforce has been moving connected apps and External Client Apps toward mandatory PKCE, with no admin opt-out on system apps like this one. Your org-level Require PKCE toggle being off is not relevant here, since that setting only affects apps that inherit the org default, and this one has its own requirement baked in. 

     

    The "invalid_request / missing required code challenge" error means the client side of this OAuth exchange, the Link Namespace popup itself, is not sending a code_challenge parameter even though the connected app now demands one. Since that popup is Salesforce's own UI and not something you control from Setup, you cannot fix this from your Dev Hub or Namespace org settings. Other admins have hit the same "missing required code challenge" wall on various Salesforce-owned OAuth flows since PKCE enforcement tightened, so this is worth logging as a Salesforce Support case, quoting the exact error and the Dev Hub and Namespace org IDs, so they can confirm whether it is a tracked regression tied to the PKCE rollout on that specific connected app. 

     

    Background on PKCE enforcement:

    https://help.salesforce.com/s/articleView?id=005316703&language=en_US&type=1

     

     

    Assumption: I cannot reproduce your Dev Hub, so I cannot fully confirm this is a Salesforce-side defect versus something specific to your org's Namespace Registry setup. This is inferred from the well-documented PKCE enforcement pattern and other reports of the same error on Salesforce-managed connected apps once PKCE became mandatory without an opt-out.

0/9000

I am in the process of submitting our package for AppExchange listing. Our solution is completely free to use, and we are preparing it for the Security Review.

However, during the submission process, the system is displaying a $999 security review fee, even though our listing is a free solution. As per Salesforce documentation and common guidelines, free solutions are generally exempt from this security review fee.

Could you please confirm:

  1. Whether the $999 fee is mandatory even for free AppExchange solutions.
  2. If free apps are exempt, please guide us on the exemption process or any steps required to correctly classify the solution so the fee does not appear.

We want to ensure the listing process is followed correctly and would appreciate your guidance on how to proceed.   

5 件の回答
  1. 2025年11月20日 9:50

    @Usman Khan

     

    You might be right, but in my last communication with the Security Review team, they clearly mentioned that we need to have the waiver code.  

    @Shubham Gour

    Please keep us update; As Usman suggested please raise a case from your partner account.  

     

0/9000

We are looking for a native salesforce application which can replace eventbrite and help us in event management and ticketing for gardens .  

 

#Appexchage Apps

1 件の回答
  1. 9月2日 19:19

    Hi @Janaki Reddi

     

    A few native options actually cover garden style ticketing well timed/dated admission tickets, guest checkout (no login needed for buyers), and Salesforce native data (no sync lag or external ticketing database). Here's how the leading ones stack up:

     

    A consultant's take: for garden admission/event ticketing specifically, my starting pick would be Blackthorn Events it's the most mature native option, handles payment processing and refunds itself (no separate Stripe/PayPal integration to maintain), and pairs with Experience Cloud for a public-facing ticket storefront visitors can buy from without a login. It's also the one most gardens/botanical orgs and nonprofits already use, per the vendor's own case data. 

    Two things worth confirming before you commit, since they change the recommendation: 

    • Ticket volume/pattern is this timed/dated admission (e.g. "Saturday 10am garden entry") with capacity caps, or more traditional single events (fundraisers, classes, weddings)? Blackthorn and AC Events both handle capacity based timed tickets; EventSpark leans more toward simple RSVP/registration.
    • Budget tier Blackthorn is licensed per-org and sits mid-to-high; EventSpark is the lower cost native option if this is a smaller garden with modest ticket volume.

    If you want, I can pull current AppExchange reviews/pricing details for whichever one fits your volume, or scope out what a native build/config would take if you'd rather not add a managed package at all worth knowing that's also an option here, since garden ticketing with capacity limits is buildable on standard Salesforce (Flow + Experience Cloud + a payment gateway like Stripe) if you want full control instead of a packaged app. 

     

    I hope you find the above information helpful. If it does, please mark it as Best Answer to help others too.

0/9000

Hello, 

 

I have set up the Enhanced Field History Tracking. I mapped it to a custom object I built and have set up the flow but it currently is not creating the records in the custom object I built. I am not sure were the error is.  

Salesforce Labs Enhanced Field History Tracking

 

Enhanced Field Flow.png

 

Debug Enhanced.png

 

 

 

#Appexchage Apps

3 件の回答
  1. 8月28日 21:44

    BINGO!!!  Once I learned a little Apex, I was able to get it working.  Thanks for the insight.

0/9000

I'm trying to link a namespace to my Dev Hub org so I can build a second-generation (2GP) managed package. When I click Link Namespace on the Namespace Registries tab, the OAuth popup immediately returns:

error=invalid_request&error_description=missing required code challenge   

The popup is the internal Environment Hub authorization flow (the redirect URL ends in /environmenthub/soma-callback.apexp). It looks like the flow requires a PKCE code_challenge that it isn't sending.

What I've already tried:

  • "Require Proof Key for Code Exchange (PKCE) for Supported Authorization Flows" is OFF in both the Dev Hub org and the namespace org (Setup > OAuth and OpenID Connect Settings).
  • Reproduced in Chrome and Firefox, with third-party cookies allowed and popup blockers disabled.
  • Confirmed no other Salesforce sessions were open in the browser.

Environment:

  • Both orgs are Developer Edition, instance USA1044, created August 2026.
  • Dev Hub and "Enable Unlocked Packages and Second-Generation Managed Packages" are enabled on the hub org.
  • The namespace is registered in the separate (non-Dev-Hub) org.

Has anyone hit this since the Summer '26 PKCE enforcement? Is there a connected-app or Environment Hub setting I'm missing, or is a support case the only way to link the namespace?   

1 件の回答
0/9000

Hey ya'll! I am looking for a document signing/generating solution/app for Salesforce that is low cost but good. I wanted to use SDocs, because we have used it before, but it turns out that it doesn't work with Professional edition.   

Does anyone have another suggestion?   

My client has Adobe PDF (not Sign), but I could suggest she upgrades fi that is the best solution. I am needing this, ultimately, to be able to be part of a button that can generate a contract, and another that can generate an invoice, pulling in merge fields, etc.

Thank you for your suggestions!   

1 件の回答
0/9000

We have been using the Unsubscribe app successfully in our organization for many years without issue.  Just recently, I have been receiving error messages, stating:    The record passed to the flow was neither a lead nor a contact.  

 

This link has only been used in our templates on the contact object, and I am not sure why it is suddenly failing.    The error email is also not passing the recordid or email, so I am not able to determine where it is coming from.  Has anyone encountered this issue?       

1 件の回答
  1. 8月3日 12:24

    Hi @Maria Smachetti The error indicates that the flow is receiving a record that isn't a Lead or Contact, or the record ID isn't being passed correctly. Since this started recently, check whether any email templates, flows, or automation were updated and verify that the unsubscribe link is still passing the correct Contact ID. Also review the flow debug logs to identify which record is triggering the error. If everything looks correct, check for updates to the Salesforce Labs app or contact Salesforce Support, as it may be a recent issue with the package.

0/9000

This is regarding the recent salesforce notification on the blocking of uninstalled connected apps in the org.     How do we find out if such an app(uninstalled connected app found under the Connected Apps OAuth Usage as per the guidelines) has been currently in use?  Is it decided by the LastUsedDate field from the OAuthToken object?     Appreciate your help! 

5 件の回答
0/9000

 

I'm trying to install the

Field Service Dashboards Salesforce Labs package, but the installation fails with the following error:

Our org originally had 5 dynamic dashboards. We reduced the count to 4, but the installation still fails with the same error.

Could anyone confirm how many dynamic dashboards this package creates during installation? Also, is there a version of the package that installs the dashboards as standard (run as a specific user) instead of dynamic dashboards?

1 件の回答
  1. 8月3日 11:51

    Hi @Kalaiarasi Rajendhran The installation is likely failing because the package creates additional dynamic dashboards, causing your org to exceed the allowed limit. Even after reducing your existing dashboards, the package may still require more dynamic dashboard slots than are available. Check your org's dynamic dashboard limit and the package documentation to confirm the number of dashboards it installs. If you need standard dashboards instead, see if the package provides an alternate version or contact the package owner, as the dashboard type cannot be changed during installation.

0/9000