Knowledge Base - Cloud Connect

Salesforce Authentication

Salesforce OAuth authentication models

Experlogix supports two OAuth 2.0 authentication models through a Salesforce External Client App (ECA). The ECA acts as the trusted authentication boundary between Experlogix and Salesforce, defining the permitted OAuth flows, callback URLs, scopes, access policies, and token security settings used by the integration.

Model

Best use

Key considerations

OAuth 2.0 Web Server Flow + OAuth 2.0 Refresh Token Flow

Recommended model for secure, unattended operation after an initial Salesforce authorization.

Users authenticate directly with Salesforce during setup. Ongoing access uses refresh tokens and does not require repeated logins or an active browser session.

OAuth 2.0 Client Credentials Flow

Temporary server-to-server option until Experlogix supports Refresh Token Rotation.

Uses a Consumer Key and Consumer Secret, runs as a Salesforce service user, and relies on a long-lived client secret that administrators may disable for stronger security.

Use OAuth 2.0 Web Server Flow + OAuth 2.0 Refresh Token Flow for stronger security and better connection management than Client Credentials Flow.

Connection setup in Experlogix Admin Center

During the initial connection setup, authorization is handled through Salesforce and token exchange is completed by the Experlogix backend:

  1. The user is redirected in their browser to a login page hosted and controlled by Salesforce.

  2. The user authenticates directly with Salesforce using any configured SSO, MFA, or login policies.

  3. Experlogix never receives, processes, or stores the user's Salesforce username or password.

  4. The application's client secret is not included in the browser request and is never exposed to the browser.

  5. After authorization, Salesforce returns a short-lived, one-time authorization code.

  6. The Experlogix backend exchanges this code directly with Salesforce for an access token and refresh token. The authorization code cannot be reused.

Runtime operation

After initial authorization, ongoing access is handled without browser involvement:

  • Experlogix uses the OAuth 2.0 Refresh Token Flow to obtain new access tokens as needed.

  • All token exchanges occur directly between the Experlogix and Salesforce backends.

  • Refresh tokens are stored in encrypted form and are never exposed to the browser.

  • Users do not need to remain logged in or maintain an active Salesforce session.

  • No Salesforce username or password is used during normal runtime operations.

  • Each refresh token is tied to a specific Salesforce org, External Client App, and service user.

  • Connections can be managed and revoked independently.

  • With Refresh Token Rotation enabled, each refresh token can be used only once, providing enhanced security.

Summary of benefits

  • Supports secure, unattended operation.

  • Reduces reliance on long-lived application secrets.

  • Provides explicit Salesforce authorization.

  • Improves isolation and management of individual customer connections.