Salesforce Winter ’27 Release Strengthens Security and Scales Platform Capacity
The Winter ’27 Release from Salesforce introduces significant updates aimed at enhancing security, scaling capacity, and supporting agentic architecture. Key changes include the retirement of legacy authentication methods, such as the OAuth 2.0 device flow and username-password flows, which will be restricted or retired by November 2026 and February 2027, respectively. Refresh tokens will also expire after 30 days of inactivity starting November 4, 2026, potentially impacting low-frequency integrations.
Salesforce Connect cross-org adapter and Salesforce to Salesforce features will be fully retired in Spring ’27, requiring migrations to named credentials. Connected apps will be phased out by Summer ’27 in favor of External Client Apps (ECA), which offer stronger security and clearer governance. Organizations are advised to prioritize these migrations to mitigate operational risks and ensure compliance with the new security enforcements.
The release also revisits capacity and automation decisions, with higher Apex heap limits, Elastic Async Apex Jobs (Beta) for handling demand spikes, and improvements in Flow and sharing settings. These changes allow for revisiting and potentially simplifying existing workarounds designed to navigate previous platform constraints.
For agentic systems, Winter ’27 provides building blocks like Multi-Agent Orchestration, which is generally available as of August 2026. This feature enables the composition of specialist agents without custom glue code, supporting streaming responses and handoff across various channels. Early architectural decisions are crucial for integrating these capabilities effectively.