Skip to content

Migration guide · Salesforce Modernization

SOAP API login() to OAuth migration

SOAP API login() callsOAuth 2.0 (connected apps / external client apps)

Short answer

Salesforce is retiring the SOAP API login() call, so integrations that sign in with a username, password and security token must move to OAuth 2.0 flows. The migration finds every integration that uses login(), switches it to OAuth with an integration user, and tests it before the deadline.

Why firms make this move

Older integrations, scripts and middleware often authenticate with SOAP login(). Salesforce has announced its retirement, with a deadline in 2027 (check Salesforce's current release notes for the exact date). Missing it breaks data feeds silently. The fix is usually straightforward for each integration, but finding them all is the hard part.

What moves

  • Inventory of integrations and scripts using login()
  • Connected apps or external client apps for OAuth
  • Integration users with least-privilege access
  • Updated middleware and script credentials

How the data maps

FromTo
Username + password + tokenOAuth 2.0 client credentials or JWT bearer flow
Shared admin loginDedicated integration user
Hard-coded credentialsSecured connected app configuration

See the field-by-field map ↓

What to watch out for

  • Integrations nobody remembers owning
  • Vendor tools that need an update from the vendor
  • Integration user licences
  • Testing in a sandbox first

How Vantage Point runs the migration

  1. Find every login() caller using login history and API logs
  2. Prioritize by business impact
  3. Create connected apps and integration users
  4. Switch each integration to OAuth and test
  5. Monitor login history after cutover

Typical timeline

Typically 2 to 6 weeks, depending on the number of integrations.

Frequently asked questions

How do we find integrations using SOAP login()?

Login history and API event logs show which users and apps authenticate with SOAP login(). We combine them with an integration inventory.

Do we need integration user licences?

Salesforce provides integration user licences in many editions. Using them is also good security practice.

Last reviewed October 2, 2026 by the Vantage Point team. Browse all migration paths →

Field-level map

SOAP API login() to OAuth: field by field

5 mappings we start from on this migration, 5 of which need a transform, a lookup or a decision. Every project gets its own signed-off version; this is the baseline.

FromToHowNotes
Integration user + password + tokenlogin() credentials External client app / connected appOAuth client credentials or JWT bearer flow req rebuild
login() sessionSession ID Access tokenBearer token req derive Refresh tokens or JWT handle renewal.
Integration userProfile permissions Integration user + permission setLeast-privilege scopes req rebuild
EndpointLogin URL / server URL OAuth token endpoint + instance URL— derive
IP restrictionsLogin IP ranges App policiesIP relaxation / allowed IPs manual review

Field names are the platforms' standard API names; your org's custom fields are mapped during discovery. What the "How" labels mean

How labels
direct
Value copies across unchanged.
picklist map
Each source value is mapped to a target value.
lookup
Matched to an existing record, such as a user by email.
association
Becomes a relationship between records, loaded in a later pass.
derive
Calculated or cleaned during the load.
split / concat
One field becomes several, or several become one.
rebuild
Configuration or automation that is rebuilt rather than moved.
drop
Not migrated, deliberately.
manual review
Needs a decision with your team before the load.