Salesforce connection setup
Create a customer-owned Local External Client App, retrieve its Consumer Key and Consumer Secret, and authorize one Salesforce organization in BeaconRelay.
What you are creating
The External Client App belongs to your Salesforce organization. Its credentials are used only for that BeaconRelay station and are encrypted before storage. BeaconRelay never asks for your Salesforce password or security token.
api and refresh_token only.https://staging.beaconrelay.dev/salesforce/oauth/callbackNever place it in tickets, screenshots, chat messages, logs, or source control. Paste it only into BeaconRelay's masked Consumer Secret field.
Before you begin
- Sign in to the Salesforce organization whose events BeaconRelay will receive. Create the Local External Client App in that same organization.
- Use a Salesforce administrator or a user allowed to create, edit, and delete External Client Apps.
- Choose an integration user with API access and permission to read the objects and fields required by your channels.
- Use Production / Developer in BeaconRelay for a production or Developer Edition org, and Sandbox only for a Salesforce sandbox.
Salesforce labels can vary slightly by release and translation. In a French org, Setup is Configuration, Quick Find is Recherche rapide, and External Client App Manager is Gestionnaire d'applications clientes externes.
Create the Local External Client App
- 1Open Salesforce Setup
Select the gear icon in the upper-right corner, then choose Setup (Configuration). Confirm that the avatar and organization identity belong to the org you intend to connect.
- 2Open External Client App Manager
In Quick Find (Recherche rapide), enter
External Client ApporApplication cliente externe. Select External Client App Manager (Gestionnaire d'applications clientes externes). - 3Create a new app
Select New External Client App (Nouvelle application cliente externe). Enter a display name such as
BeaconRelay, review the generated API name, and enter the email address of the administrator responsible for this connection. - 4Keep the app local
For Distribution State (État de distribution), choose Local (Locale). This setup does not require a namespace, Dev Hub, package, or AppExchange publication.
- 5Enable OAuth
Expand API (Enable OAuth Settings) or OAuth Settings. Select Enable OAuth (Activer OAuth).
- 6Enter the callback URL
In Callback URL (URL de rappel), enter
https://staging.beaconrelay.dev/salesforce/oauth/callback. The protocol, hostname, spelling, path, and trailing characters must match exactly. - 7Select only the required scopes
Move Manage user data via APIs (api) and Perform requests at any time (refresh_token, offline_access) into the selected OAuth scopes. Do not add the broad full-access scope.
- 8Enable the required security settings
Select Require Proof Key for Code Exchange (PKCE), Require Secret for Web Server Flow, and Require Secret for Refresh Token Flow. BeaconRelay uses the authorization-code web-server flow with PKCE S256. Do not enable Client Credentials Flow for this connection.
- 9Create the app
Select Create or Save. Do not try to authorize BeaconRelay immediately.
After creating the app or changing its OAuth settings or policies, wait the full 30 minutes before connecting it to BeaconRelay. An immediate invalid_client_id response usually means Salesforce has generated the credentials but has not propagated the app to its authorization service yet. Keep the same credentials and retry after the wait; do not recreate the app.
Choose who may authorize
Open the app's Policies tab and review Permitted Users. The organization administrator controls which Salesforce users can authorize the app.
- If users may self-authorize, the intended integration user approves access during the Salesforce OAuth screen.
- If you choose Admin approved users are pre-authorized, add the appropriate profile or permission set and assign it to the integration user before starting OAuth.
- After changing a policy or assignment, allow Salesforce time to propagate the change before testing again.
Find the Consumer Key and Consumer Secret
- 1Return to the app
From Salesforce Setup, open External Client App Manager and select the BeaconRelay app you just created.
- 2Open OAuth consumer details
Open Settings (Paramètres), expand OAuth Settings (Paramètres OAuth), and select Consumer Key and Secret (Clé et secret consommateur).
- 3Verify your identity
Salesforce can open a verification page and email a one-time code to your Salesforce account address. Enter the code and select Verify. If no message arrives, confirm the email address on your Salesforce user and check spam or quarantine.
- 4Copy both values
Copy the Consumer Key, then reveal and copy the Consumer Secret. The key is the OAuth
client_id. The secret is the OAuthclient_secret. Do not copy the app's API name, record ID, or verification code.
Connect the organization in BeaconRelay
- 1Open the connection form
In BeaconRelay, open Salesforce Orgs and choose Connect Salesforce.
- 2Identify the station
Enter a clear connection name. Select Production / Developer for production and Developer Edition organizations, or Sandbox for an actual Salesforce sandbox.
- 3Enter the credentials
Paste the Consumer Key and Consumer Secret into their corresponding masked fields. BeaconRelay strips leading and trailing whitespace and encrypts both values before storage.
- 4Authorize with Salesforce
Select Continue to Salesforce, sign in as the intended integration user, review the requested scopes, and approve access. If the browser blocks the popup, use BeaconRelay's same-page authorization fallback.
- 5Verify the connected identity
Back in BeaconRelay, confirm the Salesforce organization and user identity before creating channels or starting the listener. One Salesforce organization can belong to only one BeaconRelay account until that station is fully deleted.
Troubleshooting
invalid_client_idThe app has not propagated, the API name was copied instead of the Consumer Key, or the wrong environment was selected.Wait 30 minutes, recopy the Consumer Key from OAuth Settings, and verify Production/Developer versus Sandbox.redirect_uri_mismatchThe Salesforce callback differs from BeaconRelay's callback.Use https://staging.beaconrelay.dev/salesforce/oauth/callback exactly, save, and allow propagation.A namespace, Dev Hub, managed package, or AppExchange listing is not a remedy for these errors. BeaconRelay deliberately uses a customer-owned Local External Client App.
Salesforce reference: Create an External Client App in Your Org and Configuration des paramètres OAuth de l'application cliente externe.