Suggested answer

The JWT Bearer Token Flow allows a server app to authenticate to Salesforce without user interaction:

Setup:

1. Generate an RSA key pair (private key for the app, certificate/public key uploaded to the Connected App in Salesforce).
2. In the Connected App, enable "Use Digital Signatures".
3. Pre-authorize the integration user by either having them approve the app once, or enabling "Admin Approved Users Only" and adding the user profile/permission set.

Runtime flow:
4. The app creates a JWT with claims: iss (Consumer Key of Connected App), sub (Salesforce username), aud (Salesforce token endpoint), exp (expiry, max 3 minutes).
5. The app signs the JWT with its private key.
6. The app POSTs to https://login.salesforce.com/services/oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=<JWT>.
7. Salesforce validates the JWT signature using the stored certificate and returns an access_token.
8. The app uses the access token for API calls. No refresh token is issued — a new JWT must be requested when the token expires.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.