Skip to content

Salesforce Query authentication guide🔗

This is a step-by-step guide to acquiring credentials for authorizing the Salesforce Query component for use in Matillion ETL.

This guide covers both Salesforce Lightning and Salesforce Classic.

While component properties may differ between cloud data warehouses, the authentication process remains the same.


Prerequisites🔗

  • The Salesforce Query component uses either a username and password or an OAuth for third-party authentication. This guide only explains the OAuth method. Begin the OAuth entry process as described in Manage OAuth. You should then configure this OAuth entry using your Salesforce credentials, obtained as described below.
  • The callback URL, and therefore the Matillion ETL instance, must be HTTPS, not HTTP.
  • It is recommended that the callback URL be a fully qualified domain name (FQDN) and not an IP address.

Acquiring third-party credentials in Salesforce Lightning🔗

  1. Navigate to the Salesforce website. In the top-right of the homepage, hover over Login, and select Salesforce to navigate to the login page. Enter valid login credentials to continue.
  2. After you have logged in to the Salesforce dashboard, click âš™, in the top-right, then click Setup.
  3. Use the sidebar on the left to click Apps, then App Manager. In the top-right of Lightning Experience App Manager, click New Connected App.
  4. A New Connected App configuration dialog will open. Give details for the following fields:
    • Connected App Name: Give a name for the app.
    • API Name: Give a filename for the app (alternatively, use the name automatically generated from the Connected App Name).
    • Contact Email: Give an email address to be used as a point of contact for the app.
  5. Scroll down to the API (Enable OAuth Settings) section, and select the checkbox next to Enable OAuth Settings. This will reveal a new section. Give details for the following fields:

    • Callback URL: Paste the callback URL (copied from the Manage OAuth dialog in Matillion ETL earlier).
    • Selected OAuth Scopes: Select Access and manage your data (api), Perform requests on your behalf at any time (refresh_token, offline_access), and Provide access to your data via the Web (web). Click â–º, then click Save.

    Note

    The Require Proof Key for Code Exchange (PKCE) Extension for Supported Authorization Flows setting is enabled by default. You will need to disable this setting to prevent any issues occurring when completing the OAuth configuration for your Matillion ETL instance.

  6. If the app is created successfully, the browser will redirect to the newly created app's information page. In the API (Enable OAuth Settings) section, copy the strings next to Consumer Key and Consumer Secret as they will be required later, when you authorize the Salesforce Query component for use in Matillion ETL.

    Note

    • To view and copy the Consumer Secret, click Click to reveal.
    • Additionally, when copying these strings, some browsers may add a space to the end of the strings. Watch out for this, as it will cause the credentials to fail.
  7. Return to the Manage OAuth dialog in Matillion ETL to complete the OAuth configuration.

  8. When you complete the authorization process in Matillion ETL, you will be directed back to Salesforce, where you must complete a few basic steps before the OAuth is fully authorized. When completed, the Salesforce page will close, and you will return to your Matillion ETL instance.

Acquiring third-party credentials for OAuth (Client Credentials)🔗

The OAuth (Client Credentials) authentication method doesn't need a Matillion ETL OAuth entry, callback URL, or interactive browser sign-in. Instead, enter the Client ID, Client Secret, and Login URL directly into the Salesforce Query component properties.

Note

Steps to configure a Connected App vary depending on your Salesforce edition and release. Verify these steps against your own Salesforce org before following them.

  1. Navigate to the Salesforce website. In the top-right of the homepage, hover over Login, and select Salesforce to navigate to the login page. Enter valid login credentials to continue.
  2. After you have logged in to the Salesforce dashboard, click âš™, in the top-right, then click Setup.
  3. Use the sidebar on the left to click Apps, then App Manager. In the top-right of Lightning Experience App Manager, click New Connected App.
  4. Give details for the Connected App Name, API Name, and Contact Email fields.
  5. Scroll down to the API (Enable OAuth Settings) section, and select the checkbox next to Enable OAuth Settings. Give details for the following fields:
    • Callback URL: This flow doesn't use the callback URL, but Salesforce requires a value. Enter a placeholder, such as https://login.salesforce.com/services/oauth2/success.
    • Selected OAuth Scopes: Select Manage user data via APIs (api), and any other scopes your job requires. Click â–º, then click Save.
  6. Select the checkbox next to Enable Client Credentials Flow.
  7. Under Run As, select a dedicated Salesforce integration user (not a personal user account) to define the identity the component authenticates as. This user must not have MFA enforced on their profile, since the Client Credentials flow doesn't complete an interactive login.
  8. Click Save, then, on the app's information page, click Manage and Edit Policies. Set Permitted Users to Admin approved users are pre-authorized, and assign the profile or permission set for your chosen Run As user.
  9. In the API (Enable OAuth Settings) section, copy the strings next to Consumer Key and Consumer Secret. These correspond to the Client ID and Client Secret properties in the Salesforce Query component.

    Note

    To view and copy the Consumer Secret, click Click to reveal.

  10. In Matillion ETL, on the Salesforce Query component, set Authentication Method to OAuth (Client Credentials), then enter the Client ID, Client Secret, and Login URL (your Salesforce instance URL, for example, https://login.salesforce.com for production or https://test.salesforce.com for a sandbox).


Acquiring third-party credentials in Salesforce Classic🔗

  1. Navigate to the Salesforce website. In the top-right of the homepage, hover over Login, and select Salesforce to navigate to the login page. Enter valid login credentials to continue.
  2. In the Salesforce dashboard, click Setup in the top-right.
  3. Scroll down to the Quick Links section, and click Manage Apps.
  4. On the Apps page, scroll down to Connected Apps. Above the app list, click New.
  5. The New Connected App configuration dialog will open. Give details for the following fields:
    • Connected App Name: Give a name for the app.
    • API Name: Give a filename for the app (alternatively, use the name automatically generated from the Connected App Name).
    • Contact Email: Give an email address to be used as a point of contact for the app.
  6. Scroll down to the API (Enable OAuth Settings) section, and select the checkbox next to Enable OAuth Settings. This will reveal a new section. Give details for the following fields:

    • Callback URL: Paste the callback URL (copied from the Manage OAuth dialog in Matillion ETL earlier).
    • Selected OAuth Scopes: Select Access and manage your data (api), Perform requests on your behalf at any time (refresh_token, offline_access), and Provide access to your data via the Web (web). Click â–º, then click Save.

    Note

    The Require Proof Key for Code Exchange (PKCE) Extension for Supported Authorization Flows setting is enabled by default. You will need to disable this setting to prevent any issues occurring when completing the OAuth configuration for your Matillion ETL instance.

  7. If the app is created successfully, a message will appear stating, "Allow from 2-10 minutes for your changes to take effect on the server before using the connected app". Click Continue to be redirected to the newly created app's information page.

  8. In the API (Enable OAuth Settings) section, copy the strings next to Consumer Key and Consumer Secret as they will be required later, when you authorize the Salesforce Query component for use in Matillion ETL.

    Note

    • Allow 2-10 minutes before using these credentials in Matillion ETL.
    • To view and copy the Consumer Secret, click Click to reveal.
    • Additionally, when copying these strings, some browsers may add a space to the end of the string. Watch out for this, as it will cause the credentials to fail.
  9. Now return to the Manage OAuth dialog in Matillion ETL to complete the OAuth configuration.

  10. When you complete the authorization process in Matillion ETL, you will be directed back to Salesforce, where you must complete a few basic steps before the OAuth is fully authorized. When completed, the Salesforce page will close, and you will return to your Matillion ETL instance.