Walk through the JWT Bearer Token Flow for server-to-server Salesforce integration.
Suggested answer
The JWT Bearer Token Flow allows a server app to authenticate to Salesforce without user interaction:
Setup:
1. Generate an RSA key pair (private key for the app, certificate/public key uploaded to the Connected App in Salesforce).
2. In the Connected App, enable "Use Digital Signatures".
3. Pre-authorize the integration user by either having them approve the app once, or enabling "Admin Approved Users Only" and adding the user profile/permission set.
Runtime flow:
4. The app creates a JWT with claims: iss (Consumer Key of Connected App), sub (Salesforce username), aud (Salesforce token endpoint), exp (expiry, max 3 minutes).
5. The app signs the JWT with its private key.
6. The app POSTs to https://login.salesforce.com/services/oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=<JWT>.
7. Salesforce validates the JWT signature using the stored certificate and returns an access_token.
8. The app uses the access token for API calls. No refresh token is issued — a new JWT must be requested when the token expires.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.