Prompt
How do I let an agent read and write to Salesforce?
Latest observation
Oct 9, 2026
OpenAI APIWeb search: off
To let an agent read and write to Salesforce, you usually give it access through a Salesforce API integration rather than direct user login.
Common approach
1) Create a Salesforce Connected App
In Salesforce:
- Go to Setup → App Manager → New Connected App
- Enable OAuth settings
- Set a callback URL
- Select OAuth scopes such as:
apirefresh_token/offline_accessfullonly if you truly need broad access
This connected app becomes the identity your agent uses.
2) Choose an auth flow
For an agent/service, the most common options are:
- JWT Bearer Flow
Best for server-to-server agents. No human login at runtime. - OAuth 2.0 Authorization Code Flow
Best if a human admin authorizes the app once, then the agent uses refresh tokens. - Named Credentials / External Credentials
Best if you’re using Salesforce from Salesforce or supported integrations.
3) Assign permissions carefully
The agent only gets what the Salesforce integration user can access.
Create a dedicated integration user with:
- Least-privilege profile/permission set
- Object permissions for the records it should read/write
- Field-level security
- API enabled permission
4) Use the Salesforce API
Your agent can then call:
- REST API for standard CRUD
- SOQL queries for reads
- Composite API for batching
- Bulk API for large data volumes
Typical actions:
- Read Accounts/Contacts/Opportunities
- Create or update Cases/Leads/custom objects
- Search records
- Attach notes/files if permitted
Security best practices
- Use a dedicated integration user
- Grant minimum required permissions
- Restrict access by IP ranges if possible
- Store secrets in a vault
- Rotate credentials regularly
- Log all API actions
- Consider field-level restrictions for sensitive data
If you want the agent inside Salesforce
If by “agent” you mean an agentforce / Salesforce agent / Einstein bot / Apex service, the setup differs a bit:
- Use Apex classes, Named Credentials, or External Services
- Expose only approved actions
- Enforce CRUD/FLS checks in code
Quick recommendation
If this is an external AI agent or automation service, use:
- Connected App
- JWT Bearer OAuth
- Dedicated integration user
- REST API / Composite API
If you want, I can give you:
- a step-by-step setup guide
- a JWT OAuth example
- or a Python/Node.js code sample for reading/writing Salesforce.
Brands