Salesforce
API provider
Three-legged Salesforce OAuth 2.0 via a Connected App. Each end-user logs in with their own Salesforce credentials; the app acts on their behalf. Use these settings: authorizationUrl = https://login.salesforce.com/services/oauth2/authorize, tokenUrl = https://login.salesforce.com/services/oauth2/token (use test.salesforce.com for sandboxes), defaultExpiration = 1800. clientId is the Connected App’s Consumer Key, clientSecret its Consumer Secret, and tokenMetadata the instance identifier (the XXX in https://XXX.lightning.force.com/).
- API category:
Salesforce - Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow
Configuration parameters
Required
title: string; required
Human-readable label for this OAuth provider (shown to end-users during login).authorizationUrl: string; required
Provider’s OAuth2 authorization endpoint URL (where users are redirected to log in).$ENV_VARreferences anywhere in the value are resolved from the app’s environment at request time.tokenUrl: string; required
Provider’s OAuth2 token endpoint URL (where authorization codes are exchanged for access tokens).$ENV_VARreferences anywhere in the value are resolved from the app’s environment at request time.clientId: string; required
OAuth client ID issued by the provider when the app was registered. Use$ENV_VAR(the whole value) to load it from an environment variable.clientSecret: string; required
OAuth client secret issued by the provider when the app was registered. Use$ENV_VAR(the whole value) to load it from an environment variable.
Optional
bonusAccessArgs: string; optional
Extra query-string arguments appended to the authorization URL (e.g.&access_type=offline&prompt=consentfor Google refresh tokens).hosted_domain: string; optional
If set, restricts logins to accounts in this domain (e.g. for Google Workspace SSO). Where the app also accepts bearer tokens, it restricts those callers too, matched against the token’shdclaim.defaultExpiration: string; optional
Token expiration in seconds, used as a fallback when the provider does not return one (e.g.1800for Salesforce and QuickBooks).nameForScopeParameter: string; optional
Override the scope-parameter name in the authorization URL (some providers usescopesinstead ofscope).tokenMetadata: string; optional
Provider-specific metadata appended to access tokens, carrying an instance/tenant identifier where the integration needs one (the instance id for Salesforce and ServiceNow, the company Realm ID for QuickBooks). Leave blank for providers that do not need it.resource: string; optional
RFC 8707 resource indicator: the URL of the resource these tokens are for, such as an MCP server’s endpoint. Sent on the authorization request, the code exchange and the refresh grant, so the provider can issue a token audienced to that resource alone. Leave blank unless the provider asks for it; this names a resource this app calls, never an endpoint this app serves.disablePkce: true/false; optional
Set totrueto turn off PKCE (RFC 7636) for this connection, which is otherwise always on. Only for an authorization server that rejects thecode_challengeparameter instead of ignoring it, as RFC 6749 requires of parameters it does not recognize; turning PKCE off gives up the protection against a stolen authorization code, so leave this unset unless logins fail without it.
What components can use this API
Concepts:
Ingredients:
Call API endpoint(informIngredients)Call API endpoint(inrowActionsIngredients)Call list API endpoint(inrowActionsIngredients)Load list column from API endpoint(inrowActionsIngredients)Paginated API GET(inrowActionsIngredients)Render as file link(incustomShowIngredientsList)Render as image(incustomShowIngredientsList)Set via API call(insetterIngredientsList)