Explain the four main OAuth 2.0 flows available in Salesforce and their security implications.
Suggested answer
1. Web Server Flow: Best for server-side web apps. The app redirects to Salesforce login, the user authenticates, and Salesforce returns an authorization code. The server exchanges the code for an access token. Credentials never exposed to the browser. Most secure for interactive server apps.
2. User-Agent Flow: For client-side JavaScript apps. Access token is returned in the URL fragment — never sent to the server. Risk: token is exposed in browser history and referrer headers. Use with caution.
3. JWT Bearer Token Flow: Server-to-server, no user interaction. The app signs a JWT with a private key; Salesforce validates via the registered Connected App certificate and issues an access token. Ideal for automated integrations and Apex callouts requiring named credentials.
4. Username-Password Flow: App sends username + password + security token directly to Salesforce. No redirect. Highest risk — credentials embedded in app. Avoid in production; use only for trusted internal automation where other flows are not feasible.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.