Home/Blog/Salesforce Engineering
Salesforce · OAuth 2.0 · REST API

OAuth Authentication in Salesforce

A REST API exposes access to resources that a client can interact with through unique URLs and HTTP methods. OAuth is the open protocol that authorizes those calls through the exchange of tokens. Here's how to wire it up in Salesforce, end to end.

PB
Pranjal BansalSalesforce Engineer
8 min read
Apr 2024
OAuth 2.0Connected AppsPostman

OAuth is an open protocol that authorizes a client application to access data from a protected resource through the exchange of tokens. This guide walks through all five layers - from tokens and scopes to testing the flow in Postman.

What is OAuth?

OAuth lets a client application access protected resources without ever handling the user's credentials directly. Instead, it relies on short-lived tokens issued after an authorization flow. In Salesforce, a connected app receives those tokens on behalf of the client.

CLIENT APP SALESFORCE RESOURCE authorize token →
The OAuth exchange - the client authorizes via Salesforce, receives a token, and calls the protected resource

Layer 1: tokens & scope

OAuth's tokens authorize access to protected resources. Connected apps receive tokens on behalf of a client after authorization. Scopes further define which protected resources the connected app can access - you assign them when you build the app, and they ride along with the tokens during the flow.

Access Tokens

Your key to Salesforce APIs, issued on a successful flow. Salesforce supports opaque tokens and JWT-based access tokens - each with its own trade-offs.

OAuth Endpoints

The URLs you call to make authorization requests. For external web apps, use the OAuth 2.0 web server flow (authorization code grant), which protects the app's client ID and secret.

Layer 2: configure a connected app

A connected app requests access to REST API resources on behalf of the client. To do so it must be integrated with your org's REST API using OAuth 2.0. Here's how to create one:

  1. Go to Setup. Open the Setup menu in your Salesforce org.
  2. Find App Manager. Enter App Manager in the Quick Find box.
  3. New Connected App. Click the New Connected App button.
  4. Basic details. Provide name, email, and a callback URL (your org URL).
  5. Enable OAuth settings and select your OAuth scopes, then save.
  6. Manage Consumer Details. Stay on the page and open it to get the client ID and client secret needed for authentication.
Creating a new connected app in Salesforce Setup
Creating a new Connected App in App Manager
A configured connected app with OAuth settings enabled
The finished Connected App with OAuth settings enabled

Layer 3: auth providers

An Auth Provider represents an authentication provider. Only users with Customize Application and Manage Auth. Providers permissions can access this object.

  1. Go to Setup.
  2. Find Auth. Providers. Search for it in the Quick Find box.
  3. Click New.
  4. Configure. Select Provider Type: Salesforce, then enter the client ID and client secret generated by your connected app. Add default scopes: full refresh_token offline_access.
A saved Auth Provider configured for Salesforce
The saved Auth. Provider, ready to be referenced by a Named Credential

Layer 4: named credentials

To simplify authenticated callouts, specify a named credential as the callout endpoint. It bundles the URL and authentication so your Apex never handles raw secrets.

  1. Go to Setup and search for Named Credentials.
  2. New Legacy. Click the dropdown next to New, then New Legacy.
  3. Label & URL. Give a label and the URL (your org URL).
  4. Identity & protocol. Select Named Principal as the identity type and OAuth 2.0 as the protocol.
  5. Link the Auth Provider. Choose your Auth. Provider as the authentication provider and supply the scope.
A named credential configured with OAuth 2.0 and an auth provider
The Named Credential wired to the Auth. Provider over OAuth 2.0

Layer 5: test with Postman

Finally, verify the flow by requesting a token directly. Create a collection and configure a request:

  1. Method & URL. Use POST to https://test.salesforce.com/services/oauth2/token for a sandbox - replace test with login in production.
  2. Authorization: select No Auth.
  3. Header: key Content-Type, value application/x-www-form-urlencoded.
  4. Body: choose x-www-form-urlencoded and supply the credentials below.
POST /services/oauth2/token
grant_type    = password
client_id     = <your client id>
client_secret = <your secret key>
username      = 'org username'
password      = 'org password'

Heads up: the password grant is convenient for testing, but for production integrations prefer the web server (authorization code) or JWT bearer flows - they avoid storing user passwords.

Summary

REST APIs are the basis of all interactions between applications, and OAuth is what makes those interactions secure. With tokens and scopes, a connected app, an auth provider, a named credential, and a quick Postman test, you have a complete, secure OAuth 2.0 setup - letting third-party apps transmit and access data across Salesforce safely.

Wiring up a Salesforce integration?

Our Salesforce-native team ships OAuth, connected-app, and named-credential patterns across finance, healthcare, manufacturing, and aviation. Let's make yours clean and secure.

Talk to an Engineer