Okta Workflows - Salesforce Connection Becoming Unhealthy Unexpectedly (2026)

Okta Classic Engine
Okta Identity Engine
Workflows

Overview

Okta Workflows Salesforce connections may become unhealthy approximately thirty days after authorization. This occurs because, based on Salesforce's handling of access tokens, frequent token utilization prevents the token refresh process, resulting in an expired token. 

When this issue occurs, the following error can appear:

 

HTTP Error: {"error":{"status":500,"message":"invalid_grant (expired access/refresh token)"}}

 

Manually reauthorizing the connection within 30 days of the last authorization prevents this issue and maintains a healthy connection status.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Workflows
  • Salesforce Connection

Cause

A known issue exists regarding Salesforce token handling within Okta Workflows. When an access token is utilized too frequently, it stays valid in Salesforce. Because of this, Okta Workflows does not attempt to refresh the token, causing the connection to become unhealthy.

Solution

How is the Salesforce connection reauthorized?

Maintain a healthy connection status by navigating to the Connections tab in the Okta Workflows console and manually reauthorizing the Salesforce connection before the thirty-day mark.

  1. Navigate to the Connections tab in Okta Workflows.
  2. Select the Salesforce connection.
  3. Choose the Reauthorize option.
  4. Enter the required credentials to complete the authorization.

The Okta team is actively investigating a permanent resolution to this problem.

Recommended content

No recommended content found...