Authorization
You can authorize a maximum of five accounts in Salesforce.
You can create multiple Salesforce connections and manage them from your Connections page.
When creating your connection to Salesforce, use a System Administrator profile if you plan to use the following action cards:
- Activate User
- Create User
- Deactivate User
- Freeze User
- Remove User Entitlements
- Unfreeze User
- Update User
- Upload Document
Salesforce FedRAMP High tenants
Okta Workflows in Okta for Government High only supports connections made with accounts based in Salesforce High IL4 tenants.
Procedure
Use the following steps to create a Salesforce connection in Okta Workflows:
-
Either open the Connections tab in the Workflows platform, or open an Salesforce action card.
-
Click New Connection.
-
In the Connection Nickname field, enter a display name. As a best practice, use a consistent naming convention for all connections.
-
From the Environment dropdown, select your Salesforce account environment. Most accounts use a Production environment, unless you know specifically that you're using a sandbox account.
-
In the OAuth window, enter your Salesforce email and password.
If you're already logged into Salesforce, your credentials aren't required.
-
If you have a custom Salesforce domain, for example, yourcompany.mysalesforce.com, click Use Custom Domain. Enter the domain in the Custom Domain field, and then click Continue.
-
Click Allow to authorize access to your Salesforce account.
After you create a connection on one Salesforce card, you can use the same connection every time you use any Salesforce connector. You can also create multiple connections for each connector to link all your accounts and manage them from your Settings page.
A user is limited to five concurrent tokens. Salesforce remembers the last five tokens that are granted at any given time. If a sixth connection is made, then the first connection is lost.
Supported Scopes
The following OAuth scopes must be enabled in your Salesforce environment:
-
api
-
web
-
refresh_token
-
offline_access
See OAuth Tokens.