enterprise-application-connectors · prepared

Salesforce REST API connector boundary

Official-source external-client-app, OAuth client-credentials, integration-user, API-access, scope, and secret boundaries for Salesforce connectors.

version 1.0.1freshness currentobserved 2026-08-28T07:50:57Z

resource.connector.salesforce-rest-api
sha256:7b606402a6b6df8af944d3f12b93e96b88b74a35cf02b6826e0951bf1c110609

Open canonical machine JSON →

Evidence-backed facts

  1. Salesforce documents the OAuth 2.0 client credentials flow for direct server-to-server information sharing without interactive user input. informative
  2. An external client app exchanges its client credentials for an access token and calls Salesforce APIs on behalf of an explicitly assigned integration user. informative
  3. API access remains bounded by the external client app configuration, assigned OAuth scopes, integration-user permissions, and organization policy. informative
  4. Consumer keys, client secrets, and access tokens are credentials; the official flow requires protecting and rotating them and does not grant broader access than the configured integration user. informative