Sf Connected Apps
Jaganpro/sf-skills
Salesforce Connected Apps and OAuth configuration with 120-point scoring.
Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .claude/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .claude/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .agents/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .agents/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .cursor/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .cursor/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/integration-connectivity-connected-app-configure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .gemini/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .gemini/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .github/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .github/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .opencode/skills/integration-connectivity-connected-app-configure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "integration-connectivity-connected-app-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/integration-connectivity-connected-app-configure into .opencode/skills/integration-connectivity-connected-app-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-connectivity-connected-app-configure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
integration-connectivity-connected-app-configureSalesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.
Integration Connectivity Connected App Configure is an agent skill from forcedotcom/sf-skills. Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Use this skill to configure OAuth flows, JWT bearer auth, Connected Apps, and External Client Apps in Salesforce. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, ECAs, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: configuring Named Credentials for callouts (use integration-connectivity-generate), reviewing permission policies (use platform-metadata-deploy), or…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including reference files and assets (for example `README.md`, `references/example-usage.md` and `references/migration-guide.md`).
It sits in Backend & APIs, covering CRM management, OAuth and OpenID Connect and Authentication. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepWebFetchAskUserQuestionTodoWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
sfFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
INVALID_CROSS_REFERENCE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Integration Connectivity Connected App Configure loads about 2.7k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 157 tokens; SKILL.md has 1,024 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,024 words, ~2,720 tokens.
.claude/skills/integration-connectivity-connected-app-configure/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.Use this skill when the user needs OAuth app configuration in Salesforce: Connected Apps, External Client Apps (ECAs), JWT bearer setup, PKCE decisions, scope design, or migration from older Connected App patterns to newer ECA patterns.
In scope:
.connectedApp-meta.xml or .eca-meta.xml filesOut of scope — delegate elsewhere:
platform-metadata-deploy skillplatform-apex-generate skill| If the need is... | Prefer |
|---|---|
| simple single-org OAuth app | Connected App |
| new development with better secret handling | External Client App |
| multi-org / packaging / stronger operational controls | External Client App |
| straightforward legacy compatibility | Connected App |
Default guidance:
Ask for or infer:
Decide whether a Connected App or ECA is the better long-term fit using the decision table above.
| Use case | Default flow |
|---|---|
| backend web app | Authorization Code |
| SPA / mobile / public client | Authorization Code + PKCE |
| server-to-server / CI/CD | JWT Bearer |
| device / CLI auth | Device Flow |
| service account style app | Client Credentials (typically ECA) |
Read the appropriate template before generating — do not build from scratch:
| Template | Use case |
|---|---|
assets/connected-app-basic.xml | Simple API integration, minimal OAuth |
assets/connected-app-oauth.xml | Web app with full OAuth 2.0 configuration |
assets/connected-app-jwt.xml | JWT bearer / server-to-server |
assets/connected-app-canvas.xml | Embedding external apps in Salesforce UI (Canvas) |
assets/external-client-app.xml | ECA header file — all new ECA builds start here |
assets/eca-global-oauth.xml | ECA global OAuth settings (scopes, PKCE, rotation) |
assets/eca-oauth-settings.xml | ECA per-app OAuth settings |
assets/eca-policies.xml | ECA configurable policies |
If you need source-controlled ECA OAuth security metadata, retrieve it from an org first and treat the retrieved file as the schema source of truth:
sf project retrieve start --metadata ExtlClntAppOauthSecuritySettings:<AppName> --target-org <alias>Read references/security-checklist.md for the full 120-point security checklist. Favor:
Read references/testing-validation-guide.md before handoff. Confirm:
If deployment fails, check the error output for:
DUPLICATE_VALUE — a Connected App or ECA with this name already exists; rename or retrieve-then-update insteadINVALID_CROSS_REFERENCE_KEY — the externalClientApplication name in an ECA settings file doesn't match the .eca-meta.xml filename exactlyINSUFFICIENT_ACCESS_OR_READONLY — user lacks the "Manage Connected Apps" permission| Rule | Rationale |
|---|---|
| Never commit consumer secrets to source control | Credential exposure risk |
Never use Full scope by default | Unnecessary privilege; request only what the app needs |
| Always use PKCE for public clients (mobile, SPA) | Prevents auth code interception |
| Never use wildcard or overly broad callback URLs | Token interception risk |
| ECA OAuth security settings must be retrieved from org before editing | File schema is not fully documented; retrieve-first ensures accuracy |
Use <alias> placeholders in CLI commands, never hardcoded org URLs | Org URLs vary per environment |
Detect actual packageDirectory from sfdx-project.json before writing files | Projects may not use the default force-app/main/default/ layout |
Default source location (verify via sfdx-project.json → packageDirectories):
<packageDir>/connectedApps/ECA metadata spans multiple top-level source directories. Default locations (verify via sfdx-project.json):
| Directory | Metadata type | File suffix |
|---|---|---|
<packageDir>/externalClientApps/ | ExternalClientApplication | .eca-meta.xml |
<packageDir>/extlClntAppGlobalOauthSets/ | ExtlClntAppGlobalOauthSettings | .ecaGlblOauth-meta.xml |
<packageDir>/extlClntAppOauthSettings/ | ExtlClntAppOauthSettings | .ecaOauth-meta.xml |
<packageDir>/extlClntAppOauthSecuritySettings/ | ExtlClntAppOauthSecuritySettings | .ecaOauthSecurity-meta.xml |
<packageDir>/extlClntAppOauthPolicies/ | ExtlClntAppOauthConfigurablePolicies | .ecaOauthPlcy-meta.xml |
<packageDir>/extlClntAppPolicies/ | ExtlClntAppConfigurablePolicies | .ecaPlcy-meta.xml |
| Gotcha | Detail |
|---|---|
.ecaGlblOauth not .ecaGlobalOauth | The global OAuth suffix is abbreviated — using the long form will break deployment |
.ecaPlcy not .ecaPolicy | Same abbreviation pattern — the general policy suffix is short form |
.ecaOauthSecurity for security settings | Use .ecaOauthSecurity, not .ecaSecurity |
| ECA OAuth security settings are retrieve-only | Cannot be created from scratch in source — always retrieve from org first |
| Spring '26: new Connected Apps disabled by default | New orgs block Connected App creation; use ECA unless explicitly required |
| Consumer key is generated post-deploy | You cannot set the consumer key in metadata — retrieve it after first deployment |
When finishing, confirm and report in this order:
Suggested output shape:
App: <name>
Type: Connected App | External Client App
Flow: <oauth flow>
Files: <paths>
Security: <scopes, PKCE, certs, secrets, IP policy>
Next step: <deploy, retrieve consumer key, or test auth flow>
Score: <x>/120| Need | Delegate to | Reason |
|---|---|---|
| Named Credential / callout runtime config | integration-connectivity-generate | runtime integration setup |
| Deploy app metadata | platform-metadata-deploy skill | org validation and deployment |
| Apex token or refresh handling | platform-apex-generate skill | implementation logic |
| Score | Meaning |
|---|---|
| 80+ | production-ready OAuth app config |
| 54–79 | workable but needs hardening review |
| < 54 | block deployment until fixed |
| File | When to read |
|---|---|
assets/connected-app-basic.xml | Step 3 — template for simple Connected App with minimal OAuth |
assets/connected-app-oauth.xml | Step 3 — template for full OAuth 2.0 Connected App |
assets/connected-app-jwt.xml | Step 3 — template for JWT bearer / server-to-server Connected App |
assets/connected-app-canvas.xml | Step 3 — template for Canvas app embedding in Salesforce UI |
assets/external-client-app.xml | Step 3 — ECA header file template |
assets/eca-global-oauth.xml | Step 3 — ECA global OAuth settings template (PKCE, rotation, callbacks) |
assets/eca-oauth-settings.xml | Step 3 — ECA per-app OAuth settings template |
assets/eca-policies.xml | Step 3 — ECA configurable policies template |
references/oauth-flows-reference.md | Step 2 — detailed OAuth flow comparison and decision guide |
references/security-checklist.md | Step 4 — full 120-point security scoring checklist |
references/testing-validation-guide.md | Step 5 — pre-deployment validation and testing guide |
references/migration-guide.md | When migrating from Connected App to ECA patterns |
references/example-usage.md | Full end-to-end examples for common OAuth scenarios |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 14 other files (references, assets) in skills/integration-connectivity-connected-app-configure of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Integration Connectivity Connected App Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Integration Connectivity Connected App Configure this skillforcedotcom/sf-skills | 1.1k | — | ~2.7k | Automated safety check: Notes | Apache-2.0 | |
| Sf Connected AppsJaganpro/sf-skills | 424 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Sf IntegrationJaganpro/sf-skills | 424 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Implementing Zero Trust For SaaS Applicationsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Hubspot Integrationaiskillstore/marketplace | 430 | 3 repos | ~5k | Automated safety check: Pass | None | |
| Hunt Sqlielementalsouls/Claude-BugHunter | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT |
Jaganpro/sf-skills
Salesforce Connected Apps and OAuth configuration with 120-point scoring.
Jaganpro/sf-skills
Salesforce integration architecture with 120-point scoring. An agent skill from Jaganpro/sf-skills.
mukul975/Anthropic-Cybersecurity-Skills
Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…
aiskillstore/marketplace
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.
elementalsouls/Claude-BugHunter
Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
jeremylongshore/tons-of-skills-marketplace
Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Integration Connectivity Connected App Configure is an agent skill from forcedotcom/sf-skills. Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.
Integration Connectivity Connected App Configure fits situations like: configure OAuth flows; JWT bearer auth; external Client Apps in Salesforce; : user configures OAuth flows.
Run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a claude-code`. Or copy the skill folder (skills/integration-connectivity-connected-app-configure in forcedotcom/sf-skills) into .claude/skills/integration-connectivity-connected-app-configure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a codex`. Or copy the skill folder (skills/integration-connectivity-connected-app-configure in forcedotcom/sf-skills) into .agents/skills/integration-connectivity-connected-app-configure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/integration-connectivity-connected-app-configure, .gemini/skills/integration-connectivity-connected-app-configure, .github/skills/integration-connectivity-connected-app-configure and .opencode/skills/integration-connectivity-connected-app-configure in your project.
Going by SKILL.md and its folder, Integration Connectivity Connected App Configure needs the command-line tools its instructions call (sf) and credentials named INVALID_CROSS_REFERENCE_KEY. Our summary lists: A credential in INVALID_CROSS_REFERENCE_KEY. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWrite.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Integration Connectivity Connected App Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Integration Connectivity Connected App Configure: Sf Connected Apps (Jaganpro/sf-skills, 424 stars), Sf Integration (Jaganpro/sf-skills, 424 stars), Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Hubspot Integration (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,065 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.