Skip to main content
Security

What is Connected App in Salesforce?

A Connected App is the Salesforce setting that lets an outside app sign in and call Salesforce APIs through OAuth 2.0 or SAML. Salesforce issues a Consumer Key and Secret, and you control scopes, sessions and IP rules.

Clientell AI, the AI Salesforce admin, audits your Connected App setup in a read-only scan, then drafts the fixes for you to approve. See permission management

Try it in Clientell AI

“Audit my Connected App setup: show where access is too open, list who has more than they need, and draft fixes for me to approve.”

Clientell reads your org first, drafts every change, and changes nothing until you approve. Platform deployments include rollback. How security works.

Start the 14-day free trial, no card

Term Context

Category

Security

7 terms in this category

Related Terms

4

connected concepts

Glossary

66

total definitions

How does Connected App work in Salesforce?

Connected Apps are the primary mechanism for authorizing third-party applications, mobile apps, and backend services to access Salesforce data. When you create a Connected App, Salesforce generates a Consumer Key and Consumer Secret used in OAuth 2.0 flows, including Web Server (authorization code), User-Agent (implicit), JWT Bearer Token, Device, and Client Credentials flows. The Connected App configuration controls which OAuth scopes are allowed (e.g., api, refresh_token, full, web), session policies, IP restrictions, and whether admin pre-authorization is required.

Connected Apps also support SAML for SSO integration and can be used to manage Canvas apps. Admins control access to Connected Apps through profiles and permission sets, and can set policies for refresh token expiration, session timeout, and IP relaxation. The OAuth approval history provides an audit trail of which users have authorized the app. For service-to-service integrations, the JWT Bearer flow combined with a certificate and Named Credential is the recommended pattern. Clientell AI uses a Connected App with minimal scopes for secure, admin-approved access to your org's metadata.

Questions people ask

What does a Connected App do in Salesforce?

It lets an outside app sign in to Salesforce and call its APIs using OAuth 2.0 or SAML. Salesforce gives the app a Consumer Key and a Consumer Secret.

Which OAuth flows does a Connected App support?

Web Server, User-Agent, JWT Bearer, Device and Client Credentials flows, among others.

How do I control who can use a Connected App?

Use profiles and permission sets, plus session and IP policies. You can also require admin pre-authorization and set refresh token expiry.

Which OAuth flow suits service-to-service integrations?

The JWT Bearer flow with a certificate and a Named Credential is the recommended pattern.

Getting Started

Try this on your own org

Start the 14-day free trial, no card. Clientell scans read-only first and changes nothing until you approve.

14-day free trial  ·  No credit card required

SOC 2
HIPAA
GDPR
Salesforce Partner