Salesforce Service Cloud APIs · Authentication Profile

Service Cloud Authentication

Authentication

Salesforce Service Cloud APIs secures its APIs with oauth2, openIdConnect, and http-bearer across 4 declared security schemes, as derived from its OpenAPI definitions.

CloudCRMCustomer ServiceEnterpriseSalesforceSupport
Methods: oauth2, openIdConnect, http-bearer Schemes: 4 OAuth flows: API key in:

Security Schemes

chatbotAuth oauth2
· flows: authorizationCode, implicit
jwtBearer http
scheme: bearer
platform-bearer http
scheme: bearer
mcp-jwt http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://login.salesforce.com/.well-known/openid-configuration (probed 200, 2026-08-27),
  https://api.salesforce.com/.well-known/oauth-authorization-server (probed 200),
  https://api.salesforce.com/.well-known/oauth-protected-resource + the per-MCP-resource form (probed 200),
  openapi/service-cloud-einstein-bots-openapi.yml, and
  https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/intro_understanding_authentication.htm
docs: https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/intro_understanding_authentication.htm
summary:
  primary: OAuth 2.0 bearer token
  api_keys: false
  api_key_note: >-
    Salesforce issues NO API keys. Every API call carries an OAuth access token minted against a
    specific org for a specific user. There is no static credential to leak and no test/live key prefix.
  types: [oauth2, openIdConnect, http-bearer]
  mutual_tls: >-
    Supported as an org-level setting (Enforce mutual authentication for the API), not declared in
    any captured contract.
authorization_servers:
  - issuer: https://login.salesforce.com
    discovery: https://login.salesforce.com/.well-known/openid-configuration
    http_status: 200
    file: well-known/service-cloud-login-openid-configuration.json
    endpoints:
      authorization: https://login.salesforce.com/services/oauth2/authorize
      token: https://login.salesforce.com/services/oauth2/token
      userinfo: https://login.salesforce.com/services/oauth2/userinfo
      jwks: https://login.salesforce.com/id/keys
      revocation: https://login.salesforce.com/services/oauth2/revoke
      introspection: https://login.salesforce.com/services/oauth2/introspect
      registration: https://login.salesforce.com/services/oauth2/register
    response_types_supported: [code, token, 'token id_token']
    token_endpoint_auth_methods_supported: [client_secret_post, client_secret_basic, private_key_jwt]
    id_token_signing_alg_values_supported: [RS256]
    subject_types_supported: [public]
    scopes: 36
  - issuer: https://login.salesforce.com
    discovery: https://api.salesforce.com/.well-known/oauth-authorization-server
    http_status: 200
    file: well-known/service-cloud-api-oauth-authorization-server.json
    note: >-
      A REDUCED view served from the API host: authorize/token/jwks only, no registration,
      introspection or revocation, grant_types [authorization_code, refresh_token],
      token_endpoint_auth_methods [client_secret_post], scopes [api, sfap_api, refresh_token,
      einstein_gpt_api], code_challenge_methods [S256].
  - name: Sandbox
    login_host: https://test.salesforce.com
    note: Sandboxes authenticate against test.salesforce.com, not login.salesforce.com.
protected_resources:
  - resource: https://api.salesforce.com
    metadata: https://api.salesforce.com/.well-known/oauth-protected-resource
    http_status: 200
    scopes_supported: [api, sfap_api, refresh_token, einstein_gpt_api]
  - resource: https://api.salesforce.com/platform/mcp/v1/platform/sobject-all
    metadata: https://api.salesforce.com/.well-known/oauth-protected-resource/platform/mcp/v1/platform/sobject-all
    http_status: 200
    scopes_supported: [mcp_api, refresh_token]
    caveat: The per-resource path is a wildcard generator — a bogus resource name also returns 200.
schemes:
  - name: chatbotAuth
    type: oauth2
    surface: Einstein Bots Runtime API
    flows:
      - flow: authorizationCode
        authorizationUrl: https://login.salesforce.com/services/oauth2/authorize
        tokenUrl: https://login.salesforce.com/services/oauth2/token
        scopes: [chatbot_api]
      - flow: implicit
        authorizationUrl: https://login.salesforce.com/services/oauth2/authorize
        scopes: [chatbot_api]
    description: chatbotAuth supports authorization code and implicit OAuth flows.
    sources: [openapi/service-cloud-einstein-bots-openapi.yml]
  - name: jwtBearer
    type: http
    scheme: bearer
    surface: Einstein Bots Runtime API
    description: >-
      Salesforce OAuth access token obtained using the JWT Bearer flow. Use the chatbot_api scope
      with this flow to enable access to the Einstein Bots services.
    sources: [openapi/service-cloud-einstein-bots-openapi.yml]
  - name: platform-bearer
    type: http
    scheme: bearer
    surface: 'Salesforce Platform REST API (sObjects, Query, Search, Composite)'
    header: 'Authorization: Bearer <access_token>'
    description: >-
      Every REST call carries the OAuth access token. The token also determines the INSTANCE — the
      token response returns instance_url, and the API base is that instance_url plus
      /services/data/v67.0. Never hard-code a host.
  - name: mcp-jwt
    type: http
    scheme: bearer
    surface: Salesforce Hosted MCP Servers
    probed: 'POST tools/list without a token → 401 {"errors":[{"message":"JWT Token is required"}]}'
    description: >-
      MCP clients authenticate with OAuth 2.0 Authorization Code with PKCE against an External
      Client App consumer key created by a Salesforce admin, requesting the mcp_api scope.
flows:
  - name: Authorization Code with PKCE
    supported: true
    pkce: S256
    use: Interactive user consent; the flow MCP clients use.
  - name: Refresh Token
    supported: true
  - name: JWT Bearer (private_key_jwt)
    supported: true
    use: >-
      Server-to-server with no user interaction — the standard integration-user pattern for a
      Service Cloud backend. Also the documented flow for Einstein Bots.
  - name: Implicit
    supported: true
    note: Declared by the Einstein Bots spec. Deprecated by current OAuth guidance; prefer PKCE.
  - name: Client Credentials
    supported: true
    note: Requires an execution user to be assigned on the connected app.
  - name: Device Flow
    supported: true
    note: Used by `sf org login device` in the CLI.
token_shape:
  access_token: opaque
  id_token: 'JWT, RS256, verified against https://login.salesforce.com/id/keys'
  instance_binding: >-
    The token response includes instance_url and id. instance_url is the API base host for that
    org — Service Cloud has no single global API host.
  claims_supported:
    [active, address, email, email_verified, family_name, given_name, is_app_installed, language,
     locale, name, nickname, organization_id, phone_number, phone_number_verified, photos, picture,
     preferred_username, profile, sub, updated_at, urls, user_id, user_type, zoneinfo]
related:
  scopes: scopes/service-cloud-scopes.yml
  conventions: conventions/service-cloud-conventions.yml
  conformance: conformance/service-cloud-conformance.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/service-cloud-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.