Skip to main content

Salesforce Authentication

Salesforce Authorization using OAuth​

Step 1: Construct the Authorization URL

  • Build the authorization URL by combining the following components:
    • Salesforce OAuth authorization endpoint: This is typically "https://login.salesforce.com/services/oauth2/authorize".
    • Parameters:
      • client_id: The Client ID obtained from the connected app.
      • redirect_uri: The callback URL where Salesforce will redirect the user after authorization.
      • response_type: Set this to "code" to request an authorization code.
      • scope: The scopes your application requires, separated by spaces.

Step 2: Redirect the User to the Authorization URL

  • Redirect the user to the constructed authorization URL, typically by providing a link or opening it in a browser.
  • When the user clicks on the link or accesses the URL, they will be redirected to the Salesforce login page to authenticate themselves (if not already logged in).

Step 3: User Authorization and Callback

  • Once the user has successfully logged in, Salesforce will prompt them to authorize your application's requested permissions.
  • After the user authorizes the application, Salesforce will redirect them to the callback URL specified in the connected app's settings.
  • Salesforce will include an authorization code as a query parameter in the redirect URL.

Step 4: Retrieve the Authorization Code

  • In your callback URL endpoint, extract the authorization code from the query parameters of the incoming request.

Step 5: Exchange Authorization Code for Access Token and Refresh Token

  • Using the obtained authorization code, make a POST request to the Salesforce OAuth token endpoint: "https://login.salesforce.com/services/oauth2/token".
  • Include the following parameters in the request payload:
    • grant_type: Set this to "authorization_code".
    • client_id: The Client ID obtained from the connected app.
    • client_secret: The Client Secret obtained from the connected app.
    • redirect_uri: The same callback URL used in the previous steps.
    • code: The authorization code obtained from the callback.

Step 6: Receive Access Token and Refresh Token

  • Salesforce will respond to the token request with a JSON payload containing an access token, refresh token, and other details.
  • Extract the access token and refresh token from the response payload.

Salesforce Access Tokens and Refresh Tokens​

Access Tokens:

  • Salesforce Access Tokens, also known as Session IDs, are temporary authentication credentials that allow users or applications to access Salesforce resources and perform operations on behalf of an authenticated user. These tokens are obtained through the OAuth 2.0 authentication process, and they have a limited lifespan to ensure security and control over user sessions. Access Tokens are essential for making API calls to interact with Salesforce data and functionalities.

Expiration Time of Access Tokens:

  • Salesforce Access Tokens have an expiration time that is primarily based on periods of inactivity. When a token is issued, it comes with a specific lifetime, typically a few hours, during which it remains valid. However, the timer on the token only starts ticking once the token is used for the first time.
  • The expiration window of an Access Token is automatically extended if it is used at least 50% of the way through its original expiration time. Let's illustrate this with an example: Suppose a token has a lifespan of 2 hours. If you make an API call at 59 minutes after receiving the token, it will expire in 1 hour and 1 minute from that moment. However, if you make an API call exactly at the 1-hour mark, the token will be refreshed, and its validity will be extended for another two hours.
  • Refer: https://salesforce.stackexchange.com/a/335791/136754

Refresh Tokens:

  • In addition to Access Tokens, Salesforce also issues Refresh Tokens during the OAuth 2.0 authentication process. Refresh Tokens have a longer lifespan than Access Tokens and are used to obtain a new Access Token when the original one expires. These tokens provide a secure way to refresh the user's authentication without requiring them to re-enter their credentials or grant permissions again.

Timeout and Session Management:

  • Salesforce implements a session management mechanism to ensure security and limit the number of concurrent sessions. If a user attempts to log in more than five times using the same Connected App, the oldest session associated with that app will be terminated to maintain the allowed number of active sessions. Therefore, it's crucial to manage sessions efficiently and not exceed the specified limits to avoid unintended logouts and disruptions for users.
  • In summary, Salesforce Access Tokens have a dynamic expiration time that starts counting from the first API call and can be extended by utilizing the token before reaching the 50% mark of its original lifespan. For continuous access beyond the initial token's validity, Refresh Tokens can be used to obtain new Access Tokens. Managing sessions prudently is essential to avoid interference with user sessions and maintain a seamless experience for all users interacting with Salesforce through your application.