Skip to main content

 Issue:

 Namespace Registries → Link Namespace fails with 

error=invalid_request&error_description=missing required code challenge 

Connected App: SalesforceDX Namespace Registry — Require Proof Key for Code Exchange (PKCE) is checked and read-only

 (“contact Support”). 

How unlock/disable PKCE on this Connected App ? 

We need link a namespace for managed 2GP / AppExchange.  

 

#Trailhead Challenges

1 resposta
  1. Hoje, 07:37

    Hi @Yurii Osypov

     This isn't something you can fix on your side the 

    SalesforceDX Namespace Registry

     connected app is a Salesforce-owned system app (not one in your org's App Manager), so the read-only PKCE checkbox and "contact Support" message are accurate: there's no admin-level override available to you. 

     

    What's going on:

     

    Salesforce has been rolling out mandatory PKCE enforcement across connected apps/ECAs as part of its 2026 OAuth security push (the ISV-facing version of this had a May 11, 2026 compliance deadline for partner-owned apps). It looks like this got applied to Salesforce's own internal Namespace Registry connected app, but the 

    Link Namespace button's OAuth kickoff flow on the Namespace Registries page itself isn't sending a code_challenge, So the connected app rejects its own login flow. That's a Salesforce side implementation bug, not a config issue in your Dev Hub.

     

    The community thread you found (posted yesterday, still 0 replies) confirms this is recent and unresolved publicly.

     

    What to actually do:

     

    1. Check the Known Issues site first  

      Search

      issues.salesforce.com for "Namespace Registry" or "Link Namespace PKCE" if Salesforce has already logged this as a known issue, you'll get a status and any workaround/ETA without opening a duplicate case.
    2. Open a Salesforce Support case  

      Since the Connected App policy is Salesforce-managed and read only, only Salesforce Support/Engineering can adjust or fix it. File under Platform/DX or ISV Partner Support if you have a Partner account reference the exact error (error=invalid_request&error_description=missing required code challenge) and that the Connected App shows PKCE as checked and read only.

    3. Flag business impact clearly in the case  

      State explicitly that this is blocking namespace linking for a managed 2GP package intended for AppExchange that framing tends to get ISV-blocking bugs prioritized faster than a generic "error message" report.

    4. Try from a different org/browser session as a sanity check  

      Not a real fix, but worth ruling out: confirm it's not a stale OAuth session or cached Connected App config in your specific Dev Hub by attempting Link Namespace from a fresh incognito session or a different System Admin user. If it fails identically, that confirms it's server side, not local state.

    5. Hold off on other 2GP/namespace work in this org until resolved  

      Don't try to work around it with manual namespace assignment or an unlocked package as a substitute namespace linking is foundational for 2GP and AppExchange listing, and a workaround here could create a mess to unwind once Salesforce fixes the underlying bug.  

        

      Bottom line: there's no client side or admin side fix here this needs a Salesforce Support case, since you can't touch the Connected App policy on a system app that's flagged read-only. If you have a Partner/ISV support tier, use that channel rather than standard support; ISV-blocking bugs like this (can't link namespace → can't ship a 2GP/AppExchange package) tend to get escalated faster there.  

        

      I hope you find the above information helpful. If it does, please mark it as Best Answer to help others too.  

       

0/9000