Client Credentials Flow cannot connect without the read-access integration user.
Before you start
- A Salesforce integration user with read access to the objects you want to sync.
1. Copy the My Domain URL
In Salesforce Setup, find My Domain and copy the Current My Domain URL.
2. Create an External Client App
Open External Client App Manager → New External Client App.
In Salesforce Setup, open External Client App Manager and create an app for Permute. Enable OAuth, the api scope, and Client Credentials Flow. That flow lets the app request access without an interactive user sign-in during each sync.
Use your Salesforce My Domain URL in Permute. Keep the Consumer Key and Consumer Secret from this same app together.
3. Enable OAuth client credentials
Enable OAuth, add the api scope, and enable Client Credentials Flow.
4. Set the Run As user
On the app’s Policies tab, set Run As to the read-access integration user.
Salesforce requires an integration user for Client Credentials Flow. Set that user on the app’s Policies tab under Run As. Give the user read access to the objects Permute should sync.
Without Run As, the connection cannot use this flow. If only some objects are absent, check the integration user’s Salesforce permissions before changing app credentials.
5. Copy the Consumer Key and Secret
Under Settings → OAuth Settings, copy the Consumer Key and Consumer Secret.
6. Add Salesforce in Permute
In your workspace, open Connectors, select Add Connector, choose Salesforce, and name the account.
Under Sync which data?, choose an option:
| Choice | What it does |
|---|---|
| Recommended | Selects core tables. |
| Select manually | Choose the tables Permute syncs after connecting. |
Connection details
| Field or access | What to use |
|---|---|
| My Domain URL | Copy Current My Domain URL from Salesforce Setup. |
| Consumer Key and Secret | Copy both from the same External Client App. |
| Run As user | Set on the app’s Policies tab. |
- Enter My Domain URL, Consumer Key, and Consumer Secret in Permute.
- Select Connect.
7. Choose tables (manual selection)
If you chose Select manually, open the connector after connecting. Use the checkboxes to select at least one table, then select Save selection.
8. Check the first result
- Choose a Salesforce record the Run As integration user can read.
- Check the app’s api scope and Client Credentials Flow if the connection fails.
Understand the source
Salesforce source records
| Provider term | Meaning |
|---|---|
| Object | A record type, such as Account or Contact. |
| Record | One entry in an object, identified by its Salesforce ID. |
| Field | A value on the record; field-level security can hide it from a user. |
Access and source details
Keep app credentials private
The Consumer Key identifies the External Client App, and its Consumer Secret authenticates it. Copy both from that app’s OAuth Settings into Permute. If the secret is changed or compromised, copy the new value from Salesforce.
A newly created Consumer Key may need a few minutes before Salesforce accepts it, as the Permute setup screen notes.
Troubleshooting
| Problem | What to check |
|---|---|
| Connection fails | Check the domain, api scope, Client Credentials Flow, and Run As user. |
| A new key fails at first | Wait a few minutes for activation, then retry. |