Suggested answer

Remote Site Settings simply whitelist an external URL, allowing Apex callouts to that domain. They provide no credential management — authentication must be handled manually in code (headers, tokens, etc.).

Named Credentials are a more secure and powerful mechanism. They store the endpoint URL, authentication protocol (No Auth, Password, OAuth, AWS Signature V4, JWT), and credentials encrypted in Salesforce metadata. In Apex, you reference them as callout:MyCredential/path. Salesforce automatically attaches the authentication header at runtime — credentials never appear in code.

Named Credentials also support per-user authentication: each Salesforce user can have their own OAuth token stored under a Named Credential (via External Credentials in Winter '23+). This enables user-context API calls rather than a shared service account. Remote Site Settings do not support credential management at all.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.