MC1492163 - Microsoft API Hub: Zendesk OAuth tokens will require expiration and automatic refresh

Message Center

Summary

Microsoft API Hub will update Zendesk OAuth tokens to expire after 48 hours with refresh tokens expiring after 90 days, supporting automatic refresh. Existing connections must be reauthorized by early 2027 to avoid failures. Organizations should identify and reauthorize affected connections and inform developers.

Published

Oct 8, 2026

Service

Power Apps in Microsoft 365
Microsoft Power Automate in Microsoft 365

Tag

User impact
Admin impact

More information

What and why

To align with updated Zendesk security requirements, Microsoft API Hub is changing how OAuth tokens are issued and managed for Zendesk connections. New Zendesk connections and existing connections that are reauthorized after rollout will receive access tokens that expire after 48 hours, refresh tokens that expire after 90 days, and automatic token refresh support.

Rollout schedule

  • General Availability (Worldwide): Beginning in early October 2026 and expected to complete by late January 2027

Impact on your organization

Who is affected

  • Organizations using Zendesk OAuth connections in Microsoft API Hub
  • Developers who manage Zendesk connections and affected flows

Platforms and services

  • Microsoft API Hub
  • Zendesk integrations and connected workflows

What will happen

  • New Zendesk connections will receive access tokens with a 48-hour lifetime, refresh tokens with a 90-day lifetime, and automatic token refresh support.
  • Existing Zendesk connections created before this change cannot be automatically migrated to the new token model.
  • Existing connections must be reauthorized to receive expiring tokens and automatic refresh support.
  • Active new or reauthorized connections should refresh automatically.
  • Connections that remain unused for 90 days may lose refresh capability and require reauthorization when they are used again.
  • Flows that rely on existing Zendesk connections may fail until those connections are reauthorized.

Action required and recommendations

Action is required for existing Zendesk connections created before this change.

  • Identify existing Zendesk connections that require reauthorization.
  • Reauthorize those connections to receive expiring tokens and automatic refresh support.
  • Inform developers who manage Zendesk connections and affected workflows about this change.
  • Review affected flows that depend on existing Zendesk connections.

Learn more

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.