Evidence-backed facts
- Salesforce documents the OAuth 2.0 client credentials flow for direct server-to-server information sharing without interactive user input. informative
- An external client app exchanges its client credentials for an access token and calls Salesforce APIs on behalf of an explicitly assigned integration user. informative
- API access remains bounded by the external client app configuration, assigned OAuth scopes, integration-user permissions, and organization policy. informative
- Consumer keys, client secrets, and access tokens are credentials; the official flow requires protecting and rotating them and does not grant broader access than the configured integration user. informative