Overview
This guide walks you through creating a Salesforce External Client App (ECA) in your org. Once complete, you will have a Consumer Key and Consumer Secret to paste into DeepMask’s Salesforce connector — enabling your users to search records, review opportunities, and log activity from inside DeepMask.DeepMask uses OAuth 2.0 delegated authentication (authorization code + PKCE). DeepMask never stores Salesforce passwords. Every action runs as the signed-in user — DeepMask cannot see more than that user already can in Salesforce.
One DeepMask connection equals one Salesforce org. A user who works in several orgs connects each org separately.
Prerequisites
Required Access
- Salesforce org with API access — Any Lightning / Salesforce Cloud edition that can use the REST API (including Developer Edition, Enterprise, Unlimited, and sandboxes).
- Permission to create External Client Apps — A System Administrator, or a user who can open Setup → External Client App Manager.
- API Enabled on every user who will connect — this is a profile / permission-set flag in Salesforce.
What You Do Not Need
- No Salesforce managed package (for a Local / bring-your-own app)
- No developer tools or command line
- No service account or shared integration user
Step 1 — Allow External Client Apps
1
Open Salesforce Setup
Sign in to the org you want to connect. Click the gear icon and choose Setup.
2
Enable ECA creation
In Quick Find, type External Client App Settings. Open it and allow users to create External Client Apps if that toggle is off.
Step 2 — Create the External Client App
1
Open External Client App Manager
In Quick Find, type External Client App Manager and click New External Client App.
2
Fill in the basic details
Local means this app belongs to this org only. Do not switch Distribution State to Packaged unless you are publishing a managed package for many customer orgs.
Step 3 — Configure OAuth Settings
Still on the new app (or Settings → OAuth Settings after save), enable OAuth and apply exactly these values.Callback URL
Enter this value exactly (no trailing slash). DeepMask redirects here after Salesforce sign-in.OAuth scopes
Move exactly these three into Selected OAuth Scopes. Requesting a scope the app does not grant fails the entire login withinvalid_scope.
Leave every other scope in Available (do not add Full access, Web, Chatter, Visualforce, or custom permissions).
Flow Enablement
Match this checkbox set:DeepMask’s connector uses Authorization Code (the user signs in) plus the Client ID and Client Secret you paste in DeepMask. User actions still run as that Salesforce user — not as a client-credentials service account.
Security
Match this checkbox set:PKCE and refresh-token rotation stay on. JWT-based access tokens stay off. DeepMask stores the latest refresh token when Salesforce rotates it.
Step 4 — Set OAuth Policies
Open the app → Policies (or OAuth Policies) and set:“All users may self-authorize” lets each teammate connect their own Salesforce user. If you restrict this to pre-authorized users, an admin must approve every DeepMask connection.
Step 5 — Copy the Consumer Key and Secret
1
Open OAuth Settings
In External Client App Manager, open DeepMask Salesforce Connector → Settings → OAuth Settings.
2
Reveal the credentials
Click Consumer Key and Secret. Salesforce may ask you to verify your identity.
3
Copy both values
DeepMask’s Salesforce connector asks for Client ID and Secret. Map the Salesforce labels like this:
Step 6 — Connect Salesforce in DeepMask
1
Open DeepMask
Go to chat.deepmask.io and sign in.
2
Open Connectors
In the chat toolbar, click Add connectors (or Connectors in the left navigation).
3
Start the Salesforce connector
Find the Salesforce tile and click Connect.
4
Paste Client ID and Secret
DeepMask prompts for two fields:
- Client ID — the Consumer Key from Step 5
- Secret — the Consumer Secret from Step 5
login.salesforce.com) or Sandbox (test.salesforce.com).5
Save and sign in to Salesforce
Click Save & Connect. A Salesforce login window opens. Sign in as the Salesforce user who should own this connection and approve the requested scopes.
6
Confirm
You return to DeepMask. The Salesforce tile shows Connected. The AI can now use Salesforce in this workspace, limited to that user’s records.
Ask something like “What’s on my plate in Salesforce today?” or “Find open opportunities I own.” If the connector is live, DeepMask will call Salesforce and return records with Lightning links.
Local / Developer Edition orgs: if Salesforce returns Cross-org OAuth flows are not supported, start the login at the org’s My Domain (
https://<mydomain>.my.salesforce.com) instead of login.salesforce.com. Sandboxes use test.salesforce.com or the sandbox My Domain.Troubleshooting
”invalid_scope” during sign-in
Cause: DeepMask requestedapi, refresh_token, and openid, but the ECA does not grant one of them (usually openid).
Resolution: Edit the ECA OAuth scopes, enable all three, save, wait a few minutes, and retry.
”Cross-org OAuth flows are not supported”
Cause: A Local ECA cannot complete OAuth atlogin.salesforce.com / test.salesforce.com for some Developer Edition and scratch orgs.
Resolution: Authorize at the org My Domain (https://<name>.my.salesforce.com/services/oauth2/authorize). Production packaged apps use login.salesforce.com.
Redirect URI mismatch
Cause: The Callback URL in the ECA does not exactly match the URL DeepMask sends. Resolution: In OAuth Settings, the Callback URL must be exactly:https://chat.deepmask.io/api/user/connectors/oauth/callback
No trailing slash. No http:// variant.
User connects but sees no records (or only some)
Cause: Salesforce sharing, field-level security, or a missing API Enabled permission — not a DeepMask bug. Resolution:- Confirm the user can see the same records in the Salesforce UI.
- Confirm their profile has API Enabled.
- Custom objects must be queryable and visible to that profile.
”Need admin approval” or users cannot self-authorize
Cause: Permitted Users is not “All users may self-authorize”, or the org requires admin-approved apps. Resolution: Set Permitted Users to All users may self-authorize, or pre-authorize each user on the ECA Policies page.Login works in Salesforce but DeepMask still says unauthorized
Cause: The access token expired, the refresh token was revoked, or the org instance URL stored on the connection is stale. Resolution: Disconnect and connect again. After a sandbox refresh or My Domain change, users must reconnect so DeepMask stores the newinstance_url.
Security & Privacy
Delegated authentication
- Every Salesforce call runs as the signed-in user.
- Salesforce enforces profile, permission sets, sharing rules, and field-level security. DeepMask adds no extra visibility.
- Removing a user’s Salesforce access immediately removes what they can see in DeepMask.
No stored passwords
DeepMask stores a refresh token and the org host (instance_url), encrypted at rest. It does not store the user’s Salesforce password.
Writes are confirmed; there is no delete
Users can create and update records (and log calls / meetings). Updates and multi-record creates require an explicit confirm after a preview. DeepMask cannot delete Salesforce records.Revoking access
- In DeepMask → Connectors → Salesforce → Disconnect.
- In Salesforce Setup → External Client App Manager → your app → revoke or delete the app.
Questions about data residency, compliance, or security? Contact DeepMask support at support@deepmask.io.