BeaconRelay
Sign inStart free
Salesforce event gateway

BeaconRelay

Reliable, replayable and verifiable Salesforce events for applications and AI agents.

Customer-owned OAuth. Payloads encrypted at rest.Independent org access and owner-controlled reveal
Persist before delivery 12-attempt retry cycle Signed delivery evidence
Transport contract

From Salesforce signal to accepted request.

Three controlled stages replace the fragile chain of listener code, temporary memory, and blind HTTP calls. One event identity follows the payload from source to outcome.

  1. 01 OAuth secured
    Authorize the source

    Authorize through a Local External Client App owned by the Salesforce customer.

    • Per-org Consumer Key and Secret
    • Authorization Code + PKCE
    • Independent revocation boundary
  2. 02 Encrypted checkpoint
    Persist before delivery

    Commit the event before any outbound request can succeed or fail.

    • AES-256-GCM payload
    • Stable event identity
    • SHA-256 + Ed25519 proof
  3. 03 Managed delivery
    Deliver with evidence

    Send to HTTPS, classify the response, and keep working when the receiver cannot.

    • 12-attempt retry cycle
    • Dead Letter redrive
    • Responses and signed receipts
ReceivedEncryptedSignedAccepted or recoverable
Operational clarity

Follow every event from Salesforce to acceptance.

Inspect attempts, receiver responses, route changes, incidents, cryptographic fingerprints and receipts from one workspace.

Explore delivery mechanics
BeaconRelay event inbox and monitoring interface
Event inbox, listener health and delivery evidence in one station view.
  1. 01 Durable first
    Reliable by default

    Retryable failures follow a jittered schedule. Broker failure cannot erase a database-backed event.

    • Persisted before delivery
    • 12-attempt retry cycle
    • Explicit Dead Letter state
  2. 02 Context retained
    Replayable with context

    Replay cursors resume Salesforce streams and failed deliveries retain their complete attempt trail.

    • Durable replay cursor
    • Response history
    • Manual Dead Letter redrive
  3. 03 Customer verifiable
    Verifiable afterward

    Cryptographic evidence lets customers independently verify what BeaconRelay handled.

    • SHA-256 fingerprint
    • Ed25519 signature
    • Signed delivery receipt
PersistedRecoverableTraceableVerifiable
Private by default

Payloads stay encrypted and concealed until their owner asks to inspect them.

Salesforce payloads and captured receiver responses are stored as authenticated AES-256-GCM envelopes. The event inbox shows encrypted-byte metadata, not plaintext. Only the signed-in owner can request an in-product reveal, and every reveal is integrity-checked, rate-limited, returned with no-store, and written to the audit trail.

Encrypted at restPlaintext payload columns remain empty on the active gateway path.
Owner-controlled revealAuthenticated, CSRF-protected and separately rate-limited.
Automatic content expiryPlan retention removes terminal payload and response content while proofs remain.
Read the encryption model
Encrypted payload Content concealed
IntegrityVerified
Reveal accessOwner only
AuditRecorded
Customer-owned Salesforce access

One extra setup step. One less shared secret.

A shared vendor OAuth app is faster to approve, but it reuses one client-credential boundary across every customer authorization. BeaconRelay rejects that shortcut. Every new station uses a Local External Client App created inside the Salesforce organization whose events it transports.

This does not mean BeaconRelay cannot process authorized events. Transport requires that access. It means the authorization is explicit, scoped to one organization, encrypted per station, and independently controlled by the customer.

Review the Salesforce setup
Your org, your applicationThe Local External Client App lives in your Salesforce org. No BeaconRelay package, namespace, or shared global Consumer Secret is required.
Your revocation switchDisable or revoke BeaconRelay from Salesforce without depending on another tenant's credentials or release cycle.
Your independent rotationReplace one station's Consumer Key and Secret without changing the OAuth boundary used by another customer.
Smaller credential blast radiusEach station uses a different client secret, so rotating or revoking one app does not require changing another customer's OAuth client credentials.
01Create onceA Salesforce administrator creates one Local External Client App in the org being connected.
02Allow propagationSalesforce can take up to 30 minutes to recognize a new app or changed OAuth policy.
03Operate continuouslyBeaconRelay encrypts the credentials and handles access-token refresh, listener health, replay, and delivery.

Required for every new BeaconRelay station. The one-time setup is deliberate security work that keeps customer authorization boundaries independent.

Built for event-driven work

One Salesforce event. Many useful destinations.

Configure the Salesforce objects and operations that matter, point BeaconRelay at one HTTPS receiver per station, and keep transport concerns outside your business logic.

Business automation

Trigger backend workflows without Apex callout plumbing.

Move Opportunity, Case, Lead, Contract, or custom-object changes into your application while BeaconRelay owns reconnection, retry timing, and failure state.

AI agents

Feed agents durable business events, not fragile callbacks.

Give an agent stable event IDs, delivery history, signatures, and controlled payload access so asynchronous work can be traced and retried.

Data operations

Keep services and internal data products in step with Salesforce.

Route selected changes to ingestion APIs, analytics workers, search indexes, or customer systems without polling Salesforce for every update.

Audit and support

Answer what happened after the webhook left.

Correlate a friendly event ID with attempts, receiver responses, route changes, incidents, fingerprints, signatures, and downloadable receipts.

OAuth + PKCE Listener health Durable replay cursor Receiver rerouting Response classification Incident lifecycle
Beyond the five-dollar script

Receiving a webhook is easy. Operating a Salesforce event gateway is the work.

A small listener can prove the happy path. Production means owning token refresh, CometD lifecycle, replay positions, durable queues, retry policy, concurrency, observability, encryption, redrive controls, and evidence every day.

Start with the transport ready
Operational concernDo it yourselfBeaconRelay
Salesforce connectivityImplement OAuth refresh, CometD reconnect, listener ownership and health checks.Own one Local External Client App; BeaconRelay handles encrypted credentials, refresh, reconnect, and listener health.
Event durabilityDesign persistence, broker recovery, replay deduplication and worker locking.Event is encrypted and committed before the first outbound request.
Failed deliveryClassify HTTP and network failures, schedule jittered retries, build a DLQ and redrive.Twelve-attempt cycle, Retry-After support, Dead Letter and owner-authorized redrive.
Changing receiversMigrate queued work safely and preserve where every attempt was sent.Reroute eligible pending events to the current receiver with route history.
Debugging and proofBuild logs, incident state, response capture, correlation IDs and cryptographic evidence.Event inbox, monitoring, encrypted responses, stable IDs, signatures and receipts.
Security lifecycleProtect secrets, prevent SSRF, scope access, rotate keys and enforce retention.Encrypted tokens and payloads, HTTPS validation, owner scoping, audited reveal and expiry.
Plans

Pay for unique event capacity, not failures.

Retries and redrives are included and never counted twice. Every plan includes monitoring, replay, encryption and delivery signatures.

TrialFree14 days
2,500

events total

  • 1 Salesforce station
  • 1 channel total
  • 7-day payload retention
  • Documentation
Start free
Startup19 EURper month
10,000

events / month

  • 1 Salesforce station
  • 2 channels total
  • 7-day payload retention
  • Standard email
Choose Startup
Business199 EURper month
1,000,000

events / month

  • 5 Salesforce stations
  • 15 channels total
  • 30-day payload retention
  • Priority email
Choose Business
EnterpriseCustomcontracted capacity
5M+

events / month

  • Contracted Salesforce stations
  • Contracted channels
  • 90+ day payload retention
  • Dedicated support + SLA
Contact sales
Detailed comparison

Choose capacity without losing reliability.

Core transport behavior is included on every plan. Paid tiers increase event volume, Salesforce organizations, channels, retention, and support.

CapabilityTrialStartupGrowthBusinessEnterprise
PriceFree19 EUR / month49 EUR / month199 EUR / monthCustom
Access period14 daysMonthlyMonthlyMonthlyContracted
Unique events2,500 total10,000 / month100,000 / month1,000,000 / month5M+ / month
Salesforce stations1125Contracted
Channels1 total2 total6 total15 totalContracted
HTTPS destinations1 / station1 / station1 / station1 / stationContracted
Payload retention7 days7 days14 days30 days90+ days
Monitoring and replayIncludedIncludedIncludedIncludedIncluded
Automatic retriesIncludedIncludedIncludedIncludedIncluded
Dead Letter redriveIncludedIncludedIncludedIncludedIncluded
Encryption at restIncludedIncludedIncludedIncludedIncluded
Delivery signaturesIncludedIncludedIncludedIncludedIncluded
SupportDocumentationStandard emailEmailPriority emailDedicated + SLA

One destination per station. At quota exhaustion, newly received events pause durably; BeaconRelay does not silently discard them. Payload expiry removes content from terminal events while retaining hashes, signatures, receipts and operational metadata.

Build on a transport layer you can explain.

Connect Salesforce. Keep the evidence.

Create your account