Boost recurring donations this giving season with the upsell prompt!Learn How >>

Salesforce Winter ’27 Update: Action Required for SOAP API Connections

updated

Salesforce is introducing an additional security requirement for SOAP API connections as part of the Winter ’27 release. This change affects Soapbox Engage customers who currently connect to Salesforce using Soapbox's SOAP API integration.

Salesforce's Announcement

Salesforce has provided the following guidance for Winter ’27:

IMPORTANT: Winter '27 introduces an additional required control to secure access to SOAP API login().

All users authenticating with SOAP API login() will require the Use Any API Auth user permission to be assigned. Lack of this user permission will result in the SOAP API login() request being rejected with an INSUFFICIENT_ACCESS error response.

What does this mean?

Salesforce is adding a new permission requirement for users that authenticate through the SOAP API login() operation.

Beginning with Winter ’27 enforcement, the Salesforce user used for a SOAP API connection must have the Use Any API Auth System Permission. If the user does not have this permission, Salesforce will reject the authentication request.

This requirement applies to existing SOAP API connections as well as new connections.

How does this affect Soapbox Engage?

If your organization connects Soapbox Engage to Salesforce using our current SOAP API authentication, the Salesforce user associated with your Soapbox Engage connection will need the Use Any API Auth permission.

Without this permission, Soapbox Engage will no longer be able to authenticate with Salesforce. Transactions can continue to process successfully through Soapbox Engage, but the corresponding records may not be created in Salesforce.

During our testing of the Winter ’27 release, we confirmed that a Soapbox Engage Salesforce connection without this permission returned the following error:

INSUFFICIENT_ACCESS: SOAP API login() requires the Use Any API Auth user permission.

We also confirmed that assigning the permission restored the existing connection without requiring the Salesforce username, password, or security token to be re-entered.

What do I need to do?

A Salesforce administrator should assign the Use Any API Auth System Permission to the Salesforce user currently connected to Soapbox Engage.

To do so:

  1. In Salesforce, navigate to Setup → Permission Sets.
  2. Create a new permission set or edit an appropriate existing permission set.
  3. Under System Permissions, enable Use Any API Auth.
  4. Assign the permission set to the Salesforce user used by your Soapbox Engage integration.
  5. In Soapbox Engage, navigate to the Diagnostics View and confirm that your Salesforce credentials are working.

Your existing Soapbox Engage Salesforce credentials should not need to be updated after the permission is assigned.

For complete instructions, including steps for confirming your connection, see:

Salesforce Error: SOAP API login() requires the Use Any API Auth user permission

When should I make this change?

We recommend making this change before Salesforce enforces the Winter ’27 requirement for your organization. This helps prevent an interruption in records being sent from Soapbox Engage to Salesforce.

If you are unsure which Salesforce user is connected to Soapbox Engage or need assistance confirming your connection, please submit a ticket.

Have more questions? Submit a request
Article is closed for comments.