BeaconRelay Staging
Back to the operating guide
Customer connection guide

Salesforce connection setup

Create a customer-owned Local External Client App, retrieve its Consumer Key and Consumer Secret, and authorize one Salesforce organization in BeaconRelay.

OAuth with PKCEProduction and sandbox
Connection boundary

What you are creating

The External Client App belongs to your Salesforce organization. Its credentials are used only for that BeaconRelay station and are encrypted before storage. BeaconRelay never asks for your Salesforce password or security token.

DistributionLocal and owned by your Salesforce organization.
OAuth scopesapi and refresh_token only.
Callback URLhttps://staging.beaconrelay.dev/salesforce/oauth/callback
Protect the Consumer Secret

Never place it in tickets, screenshots, chat messages, logs, or source control. Paste it only into BeaconRelay's masked Consumer Secret field.

Before you begin

  • Sign in to the Salesforce organization whose events BeaconRelay will receive. Create the Local External Client App in that same organization.
  • Use a Salesforce administrator or a user allowed to create, edit, and delete External Client Apps.
  • Choose an integration user with API access and permission to read the objects and fields required by your channels.
  • Use Production / Developer in BeaconRelay for a production or Developer Edition org, and Sandbox only for a Salesforce sandbox.

Salesforce labels can vary slightly by release and translation. In a French org, Setup is Configuration, Quick Find is Recherche rapide, and External Client App Manager is Gestionnaire d'applications clientes externes.

Create the Local External Client App

  1. 1
    Open Salesforce Setup

    Select the gear icon in the upper-right corner, then choose Setup (Configuration). Confirm that the avatar and organization identity belong to the org you intend to connect.

  2. 2
    Open External Client App Manager

    In Quick Find (Recherche rapide), enter External Client App or Application cliente externe. Select External Client App Manager (Gestionnaire d'applications clientes externes).

  3. 3
    Create a new app

    Select New External Client App (Nouvelle application cliente externe). Enter a display name such as BeaconRelay, review the generated API name, and enter the email address of the administrator responsible for this connection.

  4. 4
    Keep the app local

    For Distribution State (État de distribution), choose Local (Locale). This setup does not require a namespace, Dev Hub, package, or AppExchange publication.

  5. 5
    Enable OAuth

    Expand API (Enable OAuth Settings) or OAuth Settings. Select Enable OAuth (Activer OAuth).

  6. 6
    Enter the callback URL

    In Callback URL (URL de rappel), enter https://staging.beaconrelay.dev/salesforce/oauth/callback. The protocol, hostname, spelling, path, and trailing characters must match exactly.

  7. 7
    Select only the required scopes

    Move Manage user data via APIs (api) and Perform requests at any time (refresh_token, offline_access) into the selected OAuth scopes. Do not add the broad full-access scope.

  8. 8
    Enable the required security settings

    Select Require Proof Key for Code Exchange (PKCE), Require Secret for Web Server Flow, and Require Secret for Refresh Token Flow. BeaconRelay uses the authorization-code web-server flow with PKCE S256. Do not enable Client Credentials Flow for this connection.

  9. 9
    Create the app

    Select Create or Save. Do not try to authorize BeaconRelay immediately.

Wait for Salesforce propagation

After creating the app or changing its OAuth settings or policies, wait the full 30 minutes before connecting it to BeaconRelay. An immediate invalid_client_id response usually means Salesforce has generated the credentials but has not propagated the app to its authorization service yet. Keep the same credentials and retry after the wait; do not recreate the app.

Choose who may authorize

Open the app's Policies tab and review Permitted Users. The organization administrator controls which Salesforce users can authorize the app.

  • If users may self-authorize, the intended integration user approves access during the Salesforce OAuth screen.
  • If you choose Admin approved users are pre-authorized, add the appropriate profile or permission set and assign it to the integration user before starting OAuth.
  • After changing a policy or assignment, allow Salesforce time to propagate the change before testing again.

Find the Consumer Key and Consumer Secret

  1. 1
    Return to the app

    From Salesforce Setup, open External Client App Manager and select the BeaconRelay app you just created.

  2. 2
    Open OAuth consumer details

    Open Settings (Paramètres), expand OAuth Settings (Paramètres OAuth), and select Consumer Key and Secret (Clé et secret consommateur).

  3. 3
    Verify your identity

    Salesforce can open a verification page and email a one-time code to your Salesforce account address. Enter the code and select Verify. If no message arrives, confirm the email address on your Salesforce user and check spam or quarantine.

  4. 4
    Copy both values

    Copy the Consumer Key, then reveal and copy the Consumer Secret. The key is the OAuth client_id. The secret is the OAuth client_secret. Do not copy the app's API name, record ID, or verification code.

Connect the organization in BeaconRelay

  1. 1
    Open the connection form

    In BeaconRelay, open Salesforce Orgs and choose Connect Salesforce.

  2. 2
    Identify the station

    Enter a clear connection name. Select Production / Developer for production and Developer Edition organizations, or Sandbox for an actual Salesforce sandbox.

  3. 3
    Enter the credentials

    Paste the Consumer Key and Consumer Secret into their corresponding masked fields. BeaconRelay strips leading and trailing whitespace and encrypts both values before storage.

  4. 4
    Authorize with Salesforce

    Select Continue to Salesforce, sign in as the intended integration user, review the requested scopes, and approve access. If the browser blocks the popup, use BeaconRelay's same-page authorization fallback.

  5. 5
    Verify the connected identity

    Back in BeaconRelay, confirm the Salesforce organization and user identity before creating channels or starting the listener. One Salesforce organization can belong to only one BeaconRelay account until that station is fully deleted.

Troubleshooting

Message or symptomLikely causeWhat to check
invalid_client_idThe app has not propagated, the API name was copied instead of the Consumer Key, or the wrong environment was selected.Wait 30 minutes, recopy the Consumer Key from OAuth Settings, and verify Production/Developer versus Sandbox.
redirect_uri_mismatchThe Salesforce callback differs from BeaconRelay's callback.Use https://staging.beaconrelay.dev/salesforce/oauth/callback exactly, save, and allow propagation.
User cannot approveThe app is admin-preapproved but the user lacks the assigned profile or permission set.Review Policies and assign the integration user before retrying.
Consumer details missingThe current user lacks External Client App administration permission.Ask a Salesforce administrator for permission to create, edit, and delete External Client Apps.
Verification email missingThe Salesforce user email is incorrect, delayed, or filtered.Verify the Salesforce user email and check spam or quarantine before requesting another code.
Do not switch to package setup

A namespace, Dev Hub, managed package, or AppExchange listing is not a remedy for these errors. BeaconRelay deliberately uses a customer-owned Local External Client App.

Salesforce reference: Create an External Client App in Your Org and Configuration des paramètres OAuth de l'application cliente externe.