Skip to main content

#Generation Managed Package6 discutindo

   

Subject: Link Namespace fails: invalid_request "missing required code challenge" 

    

   Dev Hub org ID: <xyz>. Namespace org ID: <abc>. Namespace: Nativesign. 

   Namespace Registries > Link Namespace popup returns error=invalid_request&error_description=missing required code challenge. 

   The connected app "SalesforceDX Namespace Registry" has PKCE checked and locked ("contact Support"). Org-level PKCE is OFF. How can I link my namespace? 

 

#Package Manager  #Appexchage Apps  #Generation Managed Package  #Installed Packages

1 resposta
  1. 21 de set., 13:54

    This looks like a mismatch created by Salesforce's own PKCE enforcement rollout rather than something wrong in your org's configuration. The SalesforceDX Namespace Registry connected app is a Salesforce-owned system connected app used by the Namespace Registries Link Namespace flow, and its PKCE requirement is locked because Salesforce has been moving connected apps and External Client Apps toward mandatory PKCE, with no admin opt-out on system apps like this one. Your org-level Require PKCE toggle being off is not relevant here, since that setting only affects apps that inherit the org default, and this one has its own requirement baked in. 

     

    The "invalid_request / missing required code challenge" error means the client side of this OAuth exchange, the Link Namespace popup itself, is not sending a code_challenge parameter even though the connected app now demands one. Since that popup is Salesforce's own UI and not something you control from Setup, you cannot fix this from your Dev Hub or Namespace org settings. Other admins have hit the same "missing required code challenge" wall on various Salesforce-owned OAuth flows since PKCE enforcement tightened, so this is worth logging as a Salesforce Support case, quoting the exact error and the Dev Hub and Namespace org IDs, so they can confirm whether it is a tracked regression tied to the PKCE rollout on that specific connected app. 

     

    Background on PKCE enforcement:

    https://help.salesforce.com/s/articleView?id=005316703&language=en_US&type=1

     

     

    Assumption: I cannot reproduce your Dev Hub, so I cannot fully confirm this is a Salesforce-side defect versus something specific to your org's Namespace Registry setup. This is inferred from the well-documented PKCE enforcement pattern and other reports of the same error on Salesforce-managed connected apps once PKCE became mandatory without an opt-out.

0/9000

I’m currently trying to create a Managed Package from an enabled Dev Hub Org, following the  Salesforce documentation for registering a namespace: 

 

https://developer.salesforce.com/docs/atlas.en-us.sfdx_dev.meta/sfdx_dev/sfdx_dev_reg_namespace.htm

 

However, I consistently receive an error when trying to complete the configuration/create the managed package.

Issue Creating a Managed Package from a Dev Hub Org

 

I would like to understand the following:

  1. Is this error related to the Spring ’26 Connected App changes, specifically the restriction on creating new Connected Apps?
  2. If it is not related, could there be any missing or incorrect configuration in my Dev Hub Org, namespace, packaging org, or user permissions?
  3. Is there any updated Salesforce-recommended process for creating Managed Packages now that new Connected Apps can no longer be created?
  4. Is there an alternative approach or updated documentation that I should follow for creating and managing a package in the current Salesforce release?

I have already enabled Dev Hub

 and followed the namespace registration steps in the Salesforce documentation, but I’m still unable to proceed. 

 

#Salesforce Developer  #Generation Managed Package

1 resposta
  1. 18 de set., 14:30

    Raise a case. I've seen at least one other person with this issue and it seems it may be related to recent security changes on the Salesforce side (as you note in point 1)

0/9000

In a DevHub Developer Edition i would like to disable  

"

Require Proof Key for Code Exchange (PKCE) Extension for Supported Authorization Flows"

I see the option under App Manager ->

SalesforceDX Namespace Registry . 

 

I need a help to disable it as I am unable to link the namespace registry as i am getting error as invalid_request: missing required code challenge.

 

#Salesforce Admin  #Generation Managed Package

1 resposta
  1. 27 de ago., 16:07

    That error (missing required code challenge) means the SalesforceDX Namespace Registry connected app has PKCE enforced while the namespace-link flow is not sending a code challenge. Disable it on that specific connected app: 

     

    Setup, App Manager, find SalesforceDX Namespace Registry, open the row dropdown, choose Edit (not Manage), go to the API (Enable OAuth Settings) section, and uncheck Require Proof Key for Code Exchange (PKCE) Extension for Supported Authorization Flows, then Save. 

     

    The gotcha: that checkbox is on the Edit page, not under Manage then Edit Policies, which is where most people look. Give it a couple of minutes to propagate, then retry the namespace link. 

     

    Since PKCE is a security feature, only disable it for this app because the link needs it, and consider re-enabling once the namespace is linked. 

     

    if this helps, please mark it as the Best Answer so it helps the next person — thanks 🙂

0/9000

Hi,

 

I'm playing around with second generation packaging and I have a few questions.

 

Do you know if migrating between package types will be possible?

e.g. 

1GP (1st Generation Managed Package) -> 2GP 

or 1GP -> Developer Controlled Package

or 1GP -> 2GP -> Developer Controlled Package

 

Once 2GP is GA will sending the customer a 2GP url be enough to upgrade their package from a 1GP managed package?

 

Is there a rough timeline for when migration will be available or is it due to come once 2GP is GA?

 

Will the ancestor id from the 1GP managed package need to be used somewhere when building the first upgradable 2GP managed released package?

 

Is there a pilot program for the package bundling that has been mentioned in one of the recorded sessions?

 

Many Thanks

Nelson

2 comentários
0/9000