Agent skill

Integration Connectivity Connected App Configure

by forcedotcom in forcedotcom/sf-skills

Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.

Apache-2.0Auto-check: notesBackend & APIs

Install Integration Connectivity Connected App Configure

skills CLI
$ npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills integration-connectivity-connected-app-configure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/integration-connectivity-connected-app-configure .claude/skills/integration-connectivity-connected-app-configure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
integration-connectivity-connected-app-configure
GitHub stars
1.1k
Token cost
~2.7k tokens
SKILL.md length
1,024 words
Files
15 (incl. references, assets)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.

  • Works in 6 steps: Choose the app model → Choose the OAuth flow → Start from the right template → …
  • Configure OAuth flows
  • SKILL.md covers Scope, First Decision: Connected App…, Required Inputs and Workflow, plus 7 more sections
  • Calls sf; needs INVALID_CROSS_REFERENCE_KEY

What it does

Integration Connectivity Connected App Configure is an agent skill from forcedotcom/sf-skills. Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Use this skill to configure OAuth flows, JWT bearer auth, Connected Apps, and External Client Apps in Salesforce. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, ECAs, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: configuring Named Credentials for callouts (use integration-connectivity-generate), reviewing permission policies (use platform-metadata-deploy), or…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including reference files and assets (for example `README.md`, `references/example-usage.md` and `references/migration-guide.md`).

It sits in Backend & APIs, covering CRM management, OAuth and OpenID Connect and Authentication. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Configure OAuth flows
  • JWT bearer auth
  • External Client Apps in Salesforce
  • : user configures OAuth flows

Example prompts

  • “/integration-connectivity-connected-app-configure”

Requirements

  • A credential in INVALID_CROSS_REFERENCE_KEY
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWrite

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Choose the app model
  2. Choose the OAuth flow
  3. Start from the right template
  4. Apply security hardening
  5. Validate deployment readiness
  6. Handle errors

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • WebFetch
    • AskUserQuestion
    • TodoWrite

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • INVALID_CROSS_REFERENCE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Integration Connectivity Connected App Configure loads about 2.7k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 157 tokens; SKILL.md has 1,024 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~157
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWrite

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,024 words, ~2,720 tokens.

Download SKILL.mdSave it as .claude/skills/integration-connectivity-connected-app-configure/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
integration-connectivity-connected-app-configure
description
Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Use this skill to configure OAuth flows, JWT bearer auth, Connected Apps, and External Client Apps in Salesforce. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, ECAs, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: configuring Named Credentials for callouts (use integration-connectivity-generate), reviewing permission policies (use platform-metadata-deploy), or writing Apex token-handling code (use platform-apex-generate).
allowed-tools
Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWrite
metadata.version
1.1
metadata.domains
Integration
metadata.minApiVersion
57.0
metadata.relatedSkills
integration-connectivity-generate, platform-apex-generate, platform-metadata-deploy

integration-connectivity-connected-app-configure: Salesforce Connected Apps & External Client Apps

Use this skill when the user needs OAuth app configuration in Salesforce: Connected Apps, External Client Apps (ECAs), JWT bearer setup, PKCE decisions, scope design, or migration from older Connected App patterns to newer ECA patterns.

Scope

In scope:

  • .connectedApp-meta.xml or .eca-meta.xml files
  • OAuth flow selection and callback / scope setup
  • JWT bearer auth, device flow, client credentials, or auth-code decisions
  • Connected App vs External Client App architecture choices
  • Consumer key / secret / certificate handling strategy

Out of scope — delegate elsewhere:

  • Configuring Named Credentials or runtime callouts → integration-connectivity-generate
  • Deploying metadata to orgs → the platform-metadata-deploy skill
  • Writing Apex token-handling code → the platform-apex-generate skill

First Decision: Connected App or External Client App

If the need is...Prefer
simple single-org OAuth appConnected App
new development with better secret handlingExternal Client App
multi-org / packaging / stronger operational controlsExternal Client App
straightforward legacy compatibilityConnected App

Default guidance:

  • Choose ECA for new regulated, packageable, or automation-heavy solutions.
  • Choose Connected App when simplicity and legacy compatibility matter more.
  • Spring '26 note: creation of new Connected Apps is disabled by default in orgs. For new integrations, prefer External Client Apps unless Connected App compatibility is explicitly required.

Required Inputs

Ask for or infer:

  • App type: Connected App or ECA
  • OAuth flow: auth code, PKCE, JWT bearer, device, client credentials
  • Client type: confidential vs public
  • Callback URLs / redirect surfaces
  • Required scopes
  • Distribution model: local org only vs packageable / multi-org
  • Whether certificates or secret rotation are required

Workflow

1. Choose the app model

Decide whether a Connected App or ECA is the better long-term fit using the decision table above.

2. Choose the OAuth flow
Use caseDefault flow
backend web appAuthorization Code
SPA / mobile / public clientAuthorization Code + PKCE
server-to-server / CI/CDJWT Bearer
device / CLI authDevice Flow
service account style appClient Credentials (typically ECA)
3. Start from the right template

Read the appropriate template before generating — do not build from scratch:

TemplateUse case
assets/connected-app-basic.xmlSimple API integration, minimal OAuth
assets/connected-app-oauth.xmlWeb app with full OAuth 2.0 configuration
assets/connected-app-jwt.xmlJWT bearer / server-to-server
assets/connected-app-canvas.xmlEmbedding external apps in Salesforce UI (Canvas)
assets/external-client-app.xmlECA header file — all new ECA builds start here
assets/eca-global-oauth.xmlECA global OAuth settings (scopes, PKCE, rotation)
assets/eca-oauth-settings.xmlECA per-app OAuth settings
assets/eca-policies.xmlECA configurable policies

If you need source-controlled ECA OAuth security metadata, retrieve it from an org first and treat the retrieved file as the schema source of truth:

sh
sf project retrieve start --metadata ExtlClntAppOauthSecuritySettings:<AppName> --target-org <alias>
4. Apply security hardening

Read references/security-checklist.md for the full 120-point security checklist. Favor:

  • Least-privilege scopes
  • Explicit callback URLs
  • PKCE for public clients
  • Certificate-based auth where appropriate
  • Rotation-ready secret / key handling
  • IP restrictions when realistic and maintainable
5. Validate deployment readiness

Read references/testing-validation-guide.md before handoff. Confirm:

  • Metadata file naming is correct (see Gotchas below)
  • Scopes are justified
  • Callback and auth model match the real client type
  • Secrets are not embedded in source
6. Handle errors

If deployment fails, check the error output for:

  • DUPLICATE_VALUE — a Connected App or ECA with this name already exists; rename or retrieve-then-update instead
  • INVALID_CROSS_REFERENCE_KEY — the externalClientApplication name in an ECA settings file doesn't match the .eca-meta.xml filename exactly
  • INSUFFICIENT_ACCESS_OR_READONLY — user lacks the "Manage Connected Apps" permission
  • If any step fails, do not proceed to the next step — surface the error to the user with the specific message above

Rules / Constraints

RuleRationale
Never commit consumer secrets to source controlCredential exposure risk
Never use Full scope by defaultUnnecessary privilege; request only what the app needs
Always use PKCE for public clients (mobile, SPA)Prevents auth code interception
Never use wildcard or overly broad callback URLsToken interception risk
ECA OAuth security settings must be retrieved from org before editingFile schema is not fully documented; retrieve-first ensures accuracy
Use <alias> placeholders in CLI commands, never hardcoded org URLsOrg URLs vary per environment
Detect actual packageDirectory from sfdx-project.json before writing filesProjects may not use the default force-app/main/default/ layout

Show full SKILL.md (376 more words)Show less

Metadata Notes That Matter

Connected App

Default source location (verify via sfdx-project.json → packageDirectories):

  • <packageDir>/connectedApps/
External Client App

ECA metadata spans multiple top-level source directories. Default locations (verify via sfdx-project.json):

DirectoryMetadata typeFile suffix
<packageDir>/externalClientApps/ExternalClientApplication.eca-meta.xml
<packageDir>/extlClntAppGlobalOauthSets/ExtlClntAppGlobalOauthSettings.ecaGlblOauth-meta.xml
<packageDir>/extlClntAppOauthSettings/ExtlClntAppOauthSettings.ecaOauth-meta.xml
<packageDir>/extlClntAppOauthSecuritySettings/ExtlClntAppOauthSecuritySettings.ecaOauthSecurity-meta.xml
<packageDir>/extlClntAppOauthPolicies/ExtlClntAppOauthConfigurablePolicies.ecaOauthPlcy-meta.xml
<packageDir>/extlClntAppPolicies/ExtlClntAppConfigurablePolicies.ecaPlcy-meta.xml

Gotchas

GotchaDetail
.ecaGlblOauth not .ecaGlobalOauthThe global OAuth suffix is abbreviated — using the long form will break deployment
.ecaPlcy not .ecaPolicySame abbreviation pattern — the general policy suffix is short form
.ecaOauthSecurity for security settingsUse .ecaOauthSecurity, not .ecaSecurity
ECA OAuth security settings are retrieve-onlyCannot be created from scratch in source — always retrieve from org first
Spring '26: new Connected Apps disabled by defaultNew orgs block Connected App creation; use ECA unless explicitly required
Consumer key is generated post-deployYou cannot set the consumer key in metadata — retrieve it after first deployment

Output Expectations

When finishing, confirm and report in this order:

  1. App type chosen — Connected App or External Client App
  2. OAuth flow chosen
  3. Files created or updated — list each metadata file path
  4. Security decisions — scopes, PKCE, certs, secrets, IP policy
  5. Next deployment / testing step

Suggested output shape:

text
App: <name>
Type: Connected App | External Client App
Flow: <oauth flow>
Files: <paths>
Security: <scopes, PKCE, certs, secrets, IP policy>
Next step: <deploy, retrieve consumer key, or test auth flow>
Score: <x>/120

Cross-Skill Integration

NeedDelegate toReason
Named Credential / callout runtime configintegration-connectivity-generateruntime integration setup
Deploy app metadataplatform-metadata-deploy skillorg validation and deployment
Apex token or refresh handlingplatform-apex-generate skillimplementation logic

Score Guide

ScoreMeaning
80+production-ready OAuth app config
54–79workable but needs hardening review
< 54block deployment until fixed

Reference File Index

FileWhen to read
assets/connected-app-basic.xmlStep 3 — template for simple Connected App with minimal OAuth
assets/connected-app-oauth.xmlStep 3 — template for full OAuth 2.0 Connected App
assets/connected-app-jwt.xmlStep 3 — template for JWT bearer / server-to-server Connected App
assets/connected-app-canvas.xmlStep 3 — template for Canvas app embedding in Salesforce UI
assets/external-client-app.xmlStep 3 — ECA header file template
assets/eca-global-oauth.xmlStep 3 — ECA global OAuth settings template (PKCE, rotation, callbacks)
assets/eca-oauth-settings.xmlStep 3 — ECA per-app OAuth settings template
assets/eca-policies.xmlStep 3 — ECA configurable policies template
references/oauth-flows-reference.mdStep 2 — detailed OAuth flow comparison and decision guide
references/security-checklist.mdStep 4 — full 120-point security scoring checklist
references/testing-validation-guide.mdStep 5 — pre-deployment validation and testing guide
references/migration-guide.mdWhen migrating from Connected App to ECA patterns
references/example-usage.mdFull end-to-end examples for common OAuth scenarios

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (references, assets) in skills/integration-connectivity-connected-app-configure of forcedotcom/sf-skills.

  • SKILL.md
  • README.md
  • assets/connected-app-basic.xml
  • assets/connected-app-canvas.xml
  • assets/connected-app-jwt.xml
  • assets/connected-app-oauth.xml
  • assets/eca-global-oauth.xml
  • assets/eca-oauth-settings.xml
  • assets/eca-policies.xml
  • assets/external-client-app.xml
  • references/example-usage.md
  • references/migration-guide.md
  • references/oauth-flows-reference.md
  • references/security-checklist.md
  • references/testing-validation-guide.md

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Integration Connectivity Connected App Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Integration Connectivity Connected App Configure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Integration Connectivity Connected App Configure this skillforcedotcom/sf-skills1.1k—~2.7kAutomated safety check: NotesApache-2.0
Sf Connected AppsJaganpro/sf-skills424—~1.9kAutomated safety check: NotesMIT
Sf IntegrationJaganpro/sf-skills424—~1.5kAutomated safety check: PassMIT
Implementing Zero Trust For SaaS Applicationsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Hubspot Integrationaiskillstore/marketplace4303 repos~5kAutomated safety check: PassNone
Hunt Sqlielementalsouls/Claude-BugHunter4.8k—~5.5kAutomated safety check: PassMIT

Similar skills

  • Sf Connected Apps

    Jaganpro/sf-skills

    Salesforce Connected Apps and OAuth configuration with 120-point scoring.

    424 GitHub stars~1.9k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Sf Integration

    Jaganpro/sf-skills

    Salesforce integration architecture with 120-point scoring. An agent skill from Jaganpro/sf-skills.

    424 GitHub stars~1.5k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Implementing Zero Trust For SaaS Applications

    mukul975/Anthropic-Cybersecurity-Skills

    Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Hubspot Integration

    aiskillstore/marketplace

    Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects.

    430 GitHub starsUsed in 3 repos~5k tokens
    Sales & SupportAuto-check passed
  • Hunt Sqli

    elementalsouls/Claude-BugHunter

    Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~5.5k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Salesforce Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.

    2.8k GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Integration Connectivity Connected App Configure

What does Integration Connectivity Connected App Configure do?

Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Integration Connectivity Connected App Configure is an agent skill from forcedotcom/sf-skills. Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.

When should I use Integration Connectivity Connected App Configure?

Integration Connectivity Connected App Configure fits situations like: configure OAuth flows; JWT bearer auth; external Client Apps in Salesforce; : user configures OAuth flows.

How do I install Integration Connectivity Connected App Configure in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a claude-code`. Or copy the skill folder (skills/integration-connectivity-connected-app-configure in forcedotcom/sf-skills) into .claude/skills/integration-connectivity-connected-app-configure in your project. Claude Code loads it when a task matches its description.

How do I install Integration Connectivity Connected App Configure in Codex?

Run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a codex`. Or copy the skill folder (skills/integration-connectivity-connected-app-configure in forcedotcom/sf-skills) into .agents/skills/integration-connectivity-connected-app-configure in your project. Codex loads it when a task matches its description.

Can I use Integration Connectivity Connected App Configure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill integration-connectivity-connected-app-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/integration-connectivity-connected-app-configure, .gemini/skills/integration-connectivity-connected-app-configure, .github/skills/integration-connectivity-connected-app-configure and .opencode/skills/integration-connectivity-connected-app-configure in your project.

What does Integration Connectivity Connected App Configure need to run?

Going by SKILL.md and its folder, Integration Connectivity Connected App Configure needs the command-line tools its instructions call (sf) and credentials named INVALID_CROSS_REFERENCE_KEY. Our summary lists: A credential in INVALID_CROSS_REFERENCE_KEY. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, AskUserQuestion, TodoWrite.

Does Integration Connectivity Connected App Configure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Integration Connectivity Connected App Configure safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Integration Connectivity Connected App Configure use?

Integration Connectivity Connected App Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Integration Connectivity Connected App Configure use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Integration Connectivity Connected App Configure?

Skills that share tags, products or a category with Integration Connectivity Connected App Configure: Sf Connected Apps (Jaganpro/sf-skills, 424 stars), Sf Integration (Jaganpro/sf-skills, 424 stars), Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Hubspot Integration (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Integration Connectivity Connected App Configure?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,065 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.