Skip to main content

Overview

This guide walks you through creating a Salesforce External Client App (ECA) in your org. Once complete, you will have a Consumer Key and Consumer Secret to paste into DeepMask’s Salesforce connector — enabling your users to search records, review opportunities, and log activity from inside DeepMask.
DeepMask uses OAuth 2.0 delegated authentication (authorization code + PKCE). DeepMask never stores Salesforce passwords. Every action runs as the signed-in user — DeepMask cannot see more than that user already can in Salesforce.
One DeepMask connection equals one Salesforce org. A user who works in several orgs connects each org separately.
Already connected? See the Salesforce (Enterprise) connector actions for everything the AI can do in Salesforce — finding records, summarizing pipeline, logging activity, and more.

Prerequisites

Required Access

  • Salesforce org with API access — Any Lightning / Salesforce Cloud edition that can use the REST API (including Developer Edition, Enterprise, Unlimited, and sandboxes).
  • Permission to create External Client Apps — A System Administrator, or a user who can open Setup → External Client App Manager.
  • API Enabled on every user who will connect — this is a profile / permission-set flag in Salesforce.

What You Do Not Need

  • No Salesforce managed package (for a Local / bring-your-own app)
  • No developer tools or command line
  • No service account or shared integration user
A Local External Client App only authorizes users of the org that created it. That is the correct setup for a single customer org or a sandbox. Connecting a second, unrelated org requires either a packaged ECA or a separate Local ECA in that org.

Step 1 — Allow External Client Apps

1

Open Salesforce Setup

Sign in to the org you want to connect. Click the gear icon and choose Setup.
2

Enable ECA creation

In Quick Find, type External Client App Settings. Open it and allow users to create External Client Apps if that toggle is off.

Step 2 — Create the External Client App

1

Open External Client App Manager

In Quick Find, type External Client App Manager and click New External Client App.
2

Fill in the basic details

Local means this app belongs to this org only. Do not switch Distribution State to Packaged unless you are publishing a managed package for many customer orgs.

Step 3 — Configure OAuth Settings

Still on the new app (or Settings → OAuth Settings after save), enable OAuth and apply exactly these values.

Callback URL

Enter this value exactly (no trailing slash). DeepMask redirects here after Salesforce sign-in.
The field accepts multiple URLs, one per line. You only need this one line for chat.deepmask.io.

OAuth scopes

Move exactly these three into Selected OAuth Scopes. Requesting a scope the app does not grant fails the entire login with invalid_scope. Leave every other scope in Available (do not add Full access, Web, Chatter, Visualforce, or custom permissions).

Flow Enablement

Match this checkbox set:
DeepMask’s connector uses Authorization Code (the user signs in) plus the Client ID and Client Secret you paste in DeepMask. User actions still run as that Salesforce user — not as a client-credentials service account.

Security

Match this checkbox set:
PKCE and refresh-token rotation stay on. JWT-based access tokens stay off. DeepMask stores the latest refresh token when Salesforce rotates it.
Save the app. Salesforce often takes 2–10 minutes to propagate a new ECA before the first login works.

Step 4 — Set OAuth Policies

Open the app → Policies (or OAuth Policies) and set:
“All users may self-authorize” lets each teammate connect their own Salesforce user. If you restrict this to pre-authorized users, an admin must approve every DeepMask connection.

Step 5 — Copy the Consumer Key and Secret

1

Open OAuth Settings

In External Client App Manager, open DeepMask Salesforce Connector → Settings → OAuth Settings.
2

Reveal the credentials

Click Consumer Key and Secret. Salesforce may ask you to verify your identity.
3

Copy both values

DeepMask’s Salesforce connector asks for Client ID and Secret. Map the Salesforce labels like this:
The Consumer Secret is a secret. Do not put it in chat, tickets, or a public repo. Only DeepMask’s connector settings (or your own secret store) should hold it.

Step 6 — Connect Salesforce in DeepMask

1

Open DeepMask

Go to chat.deepmask.io and sign in.
2

Open Connectors

In the chat toolbar, click Add connectors (or Connectors in the left navigation).
3

Start the Salesforce connector

Find the Salesforce tile and click Connect.
4

Paste Client ID and Secret

DeepMask prompts for two fields:
  • Client ID — the Consumer Key from Step 5
  • Secret — the Consumer Secret from Step 5
If DeepMask also asks for an environment, choose Production (login.salesforce.com) or Sandbox (test.salesforce.com).
5

Save and sign in to Salesforce

Click Save & Connect. A Salesforce login window opens. Sign in as the Salesforce user who should own this connection and approve the requested scopes.
6

Confirm

You return to DeepMask. The Salesforce tile shows Connected. The AI can now use Salesforce in this workspace, limited to that user’s records.
Ask something like “What’s on my plate in Salesforce today?” or “Find open opportunities I own.” If the connector is live, DeepMask will call Salesforce and return records with Lightning links.
Local / Developer Edition orgs: if Salesforce returns Cross-org OAuth flows are not supported, start the login at the org’s My Domain (https://<mydomain>.my.salesforce.com) instead of login.salesforce.com. Sandboxes use test.salesforce.com or the sandbox My Domain.

Troubleshooting

”invalid_scope” during sign-in

Cause: DeepMask requested api, refresh_token, and openid, but the ECA does not grant one of them (usually openid). Resolution: Edit the ECA OAuth scopes, enable all three, save, wait a few minutes, and retry.

”Cross-org OAuth flows are not supported”

Cause: A Local ECA cannot complete OAuth at login.salesforce.com / test.salesforce.com for some Developer Edition and scratch orgs. Resolution: Authorize at the org My Domain (https://<name>.my.salesforce.com/services/oauth2/authorize). Production packaged apps use login.salesforce.com.

Redirect URI mismatch

Cause: The Callback URL in the ECA does not exactly match the URL DeepMask sends. Resolution: In OAuth Settings, the Callback URL must be exactly: https://chat.deepmask.io/api/user/connectors/oauth/callback No trailing slash. No http:// variant.

User connects but sees no records (or only some)

Cause: Salesforce sharing, field-level security, or a missing API Enabled permission — not a DeepMask bug. Resolution:
  • Confirm the user can see the same records in the Salesforce UI.
  • Confirm their profile has API Enabled.
  • Custom objects must be queryable and visible to that profile.

”Need admin approval” or users cannot self-authorize

Cause: Permitted Users is not “All users may self-authorize”, or the org requires admin-approved apps. Resolution: Set Permitted Users to All users may self-authorize, or pre-authorize each user on the ECA Policies page.

Login works in Salesforce but DeepMask still says unauthorized

Cause: The access token expired, the refresh token was revoked, or the org instance URL stored on the connection is stale. Resolution: Disconnect and connect again. After a sandbox refresh or My Domain change, users must reconnect so DeepMask stores the new instance_url.

Security & Privacy

Delegated authentication

  • Every Salesforce call runs as the signed-in user.
  • Salesforce enforces profile, permission sets, sharing rules, and field-level security. DeepMask adds no extra visibility.
  • Removing a user’s Salesforce access immediately removes what they can see in DeepMask.

No stored passwords

DeepMask stores a refresh token and the org host (instance_url), encrypted at rest. It does not store the user’s Salesforce password.

Writes are confirmed; there is no delete

Users can create and update records (and log calls / meetings). Updates and multi-record creates require an explicit confirm after a preview. DeepMask cannot delete Salesforce records.

Revoking access

  • In DeepMask → Connectors → Salesforce → Disconnect.
  • In Salesforce Setup → External Client App Manager → your app → revoke or delete the app.
Either action invalidates tokens. Users must connect again to restore access.
Questions about data residency, compliance, or security? Contact DeepMask support at support@deepmask.io.