How would you implement an outbound REST callout from Salesforce to an external API securely?
Suggested answer
I would configure a Named Credential, with an External Credential for the authentication details, so the endpoint and secrets are not hardcoded in Apex. The Apex code builds an HttpRequest using the callout:NamedCredential syntax, sets timeouts, and handles non-success status codes and exceptions.
If the callout is triggered by a record change, I would run it asynchronously, for example in Queueable Apex, because callouts are not allowed after uncommitted DML in the same transaction. Unit tests use HttpCalloutMock.
What interviewers look for
Look for Named Credentials, error handling, async execution from triggers and callout mocking in tests. A pitfall is storing API keys in custom settings or code, or making synchronous callouts directly in triggers.
Original practice content; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.