Short answer
Salesforce is retiring the SOAP API login() call, so integrations that sign in with a username, password and security token must move to OAuth 2.0 flows. The migration finds every integration that uses login(), switches it to OAuth with an integration user, and tests it before the deadline.
Why firms make this move
Older integrations, scripts and middleware often authenticate with SOAP login(). Salesforce has announced its retirement, with a deadline in 2027 (check Salesforce's current release notes for the exact date). Missing it breaks data feeds silently. The fix is usually straightforward for each integration, but finding them all is the hard part.
What moves
- Inventory of integrations and scripts using login()
- Connected apps or external client apps for OAuth
- Integration users with least-privilege access
- Updated middleware and script credentials
How the data maps
| From | To |
|---|---|
| Username + password + token | OAuth 2.0 client credentials or JWT bearer flow |
| Shared admin login | Dedicated integration user |
| Hard-coded credentials | Secured connected app configuration |
What to watch out for
- Integrations nobody remembers owning
- Vendor tools that need an update from the vendor
- Integration user licences
- Testing in a sandbox first
How Vantage Point runs the migration
- Find every login() caller using login history and API logs
- Prioritize by business impact
- Create connected apps and integration users
- Switch each integration to OAuth and test
- Monitor login history after cutover
Typical timeline
Typically 2 to 6 weeks, depending on the number of integrations.
Frequently asked questions
How do we find integrations using SOAP login()?
Login history and API event logs show which users and apps authenticate with SOAP login(). We combine them with an integration inventory.
Do we need integration user licences?
Salesforce provides integration user licences in many editions. Using them is also good security practice.
