We're wiring Salesforce Hosted MCP (read-only SObject server on api.salesforce.com) through a Unity Catalog HTTP connection and an MCP service, using OAuth User-to-Machine Per User.
Login on the MCP service works and tools respond at first. After about an hour, MCP calls fail until we log in again on the service.
On the HTTP connection, access token expiration shows “Not provided by provider.” Other OAuth HTTP connections in the same workspace (different vendors) show an expiration and don’t hit this hourly cliff.
Salesforce side is an External Client App with mcp_api / refresh_token, PKCE, and JWT-based access tokens (as in Salesforce’s Hosted MCP docs). Callback uses the standard Databricks /login/oauth/http.html redirect.
Has anyone got this combo stable past ~1 hour?
Is missing expires_in on Salesforce token responses a known issue for UC / AI Gateway refresh? Any connection settings that actually help (token exchange method, client secret on refresh, etc.)—without turning off JWT on the ECA?
Has anyone seen this sort of pattern and what fixed it (or if you had to escalate to support)? Or, if you've configured a Salesforce MCP in UC AI Gateway, how do have your External Client App set up so this refresh works properply
Thanks.