Suggested answer

SLAS (Shopper Login and API Access Service) is the OAuth 2.0-based identity service that underpins SCAPI authentication for headless B2C storefronts.

SLAS provides two primary authentication flows:

1. Guest shopper flow (Public Client with PKCE) — allows anonymous shoppers to interact with the SCAPI without an account. The frontend app exchanges a PKCE code challenge/verifier for a short-lived access token.
2. Registered customer flow — allows a logged-in customer to authenticate, receive an access token and refresh token, and maintain an authenticated session across API calls.

SLAS is important for headless because:

1. Traditional B2C Commerce authentication relied on server-side sessions managed by ISML — unsuitable for stateless API calls from React, Vue, or mobile apps
2. SLAS tokens are short-lived, cryptographically signed JWTs, reducing the risk of session hijacking
3. It provides a unified, standards-based auth layer that integrates with Salesforce Identity and external IdPs

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.