Resolved -
Resolved - Working alongside our external partners and Salesforce engineering, we have successfully implemented necessary configuration changes and confirmed that core system functionality has been restored.
Service Status:
Current State: Call logging, screen pops, and record updates within the integration are now fully operational.
Temporary Workaround Note: This is a temporary workaround as we finalize long-term code-level updates to fully align with recent security policy changes enforced by Salesforce.
Root Cause & Salesforce Security Mandates:
This incident was triggered by two mandatory Salesforce security policy enforcements:
PKCE (Proof Key for Code Exchange) Requirement: Mandatory OAuth security parameters that must be generated during authentication. Permanent code implementation for this is currently in development.
Enforce Refresh Token IP Allowlisting: Salesforce policy updates for IP allowlists for Connected Apps/External Client Apps (ECAs).
What You Need to Do:
If your integration does not automatically reconnect, please log out of the Tenfold application and re-authenticate.
If you or your agents continue to experience issues, please reach out directly to our Customer Care team for assistance.
We appreciate your patience throughout this process as we worked with Salesforce to implement these platform updates.
Jul 27, 07:55 CDT
Update -
Update Message
In Progress - Following up on our previous update, our engineering team and Salesforce support have identified the next blocker in the authentication pipeline regarding IP restrictions.
Current Status:
Active Focus: While working on the Connected App configurations, we identified that IP restriction enforcement and allowlisting policy checks are blocking the OAuth refresh handshakes from completing.
Vendor Engagement: We are actively coordinating with Salesforce support and security engineers to review and align the IP allowlist requirements for our integration infrastructure.
Next Steps: Once the IP restriction rules and Connected App policies are updated and verified by Salesforce, our team will run full reconnection testing.
Public Impact: Call logging, screen pops, and record updates within the integration remain impacted during this step.
We are actively working to clear this IP restriction blocker and will share another update as soon as testing progresses. Thank you for your continued patience.
Jul 26, 22:45 CDT
Update -
Update Message
In Progress - Our team has continued working directly with Salesforce engineering through the weekend to address the connection issue.
Current Status:
Progress: Joint efforts with Salesforce engineering are bringing us closer to a resolution.
Next Steps: We are currently finalizing the remaining moving pieces needed to restore full functionality and are preparing the final rollout steps.
Public Impact: Call logging, screen pops, and record updates within the integration remain impacted until the final resolution is deployed.
We are working to resolve this as soon as possible and will provide our next update once the deployment steps are finalized. Thank you for your continued patience.
Jul 26, 14:49 CDT
Update -
In Progress - Our engineering team is actively working on applying the necessary codebase updates to support Salesforce’s PKCE authentication requirements.
Current Status:
Development Status:
Engineering is actively implementing the required code changes across our application logic.
Public Impact:
Call logging, screen pops, and record updates within the integration remain impacted until the updated release is deployed.
Next Steps & Timeline:
Once development is finalized, the release will move into validation before being scheduled for deployment. A rollout timeline will be shared as soon as code implementation is complete.
We appreciate your patience and will share another update as soon as code changes are finalized.
Jul 24, 18:14 CDT
Identified -
Salesforce Integration Connection Failure (OAuth / PKCE Error)
Identified - We have identified the root cause of the connection errors impacting the Salesforce integration popup.
A recent update to Salesforce security policies requires Proof Key for Code Exchange (PKCE) parameters during the OAuth authentication flow. As a result, connection handshakes are currently being rejected by Salesforce, preventing call logging, screen pops, and record updates within the integration.
Next Steps:
Our engineering team is actively making the required codebase updates to support PKCE authentication.
We are in active communication with Salesforce to request a temporary exception while the update is finalized and tested.
ETA & Further Updates:
We are currently completing internal testing and preparing the release for deployment.
We apologize for the disruption and appreciate your patience as we work to restore full service as quickly as possible.
Jul 24, 10:53 CDT
Update -
We are actively working with Salesforce Support Engineering to resolve the issue. Initial investigations point to an anomaly during the authentication handshake between the systems.
Our team has completed an initial joint troubleshooting session with Salesforce to isolate the root cause. Their engineering team is currently analyzing the findings, and we are awaiting their confirmation on the next steps and remediation plan. We will provide another update as soon as new information is available.
Jul 23, 21:01 CDT
Update -
We are continuing to investigate this issue.
Jul 23, 18:00 CDT
Update -
We are continuing to investigate this issue.
Jul 23, 17:43 CDT
Investigating -
Service Advisory: CRM Integration Issues
Status: Active Investigation
Impacted Feature: Company Settings -> CRM Tab
What’s Happening:
We are currently tracking an issue affecting multiple accounts where users are encountering the following error message when attempting to access or authenticate their CRM settings:
invalid_grant - expired access/refresh token
invalid_grant - ip restricted by app developer
What We Are Doing:
Our engineering team is actively investigating the root cause behind these token expirations. We are prioritizing a resolution to restore seamless connectivity as quickly as possible.
Action Required:
At this time, no action is required on your end. We recommend holding off on repeated re-authentications of your CRM integration until we have resolved the underlying issue.
Next Update:
We will provide another update as soon as we have more details, or within [e.g., 30–60 minutes]. Thank you for your patience.
Jul 23, 17:24 CDT