---
title: "Set up a connection to Salesforce"
canonical: "https://support.appfire.com/space/477986818/2560820073/Set%20up%20a%20connection%20to%20Salesforce"
format: markdown
---
## Overview

Setting up the integration is a three-part process:

1. [Select an integration user](https://appfire.atlassian.net/wiki/spaces/477986818/pages/2560820073/Set+up+a+connection+to+Salesforce#Step-1%3A-Select-an-integration-user)
2. [Add the connection to Salesforce](https://appfire.atlassian.net/wiki/spaces/477986818/pages/2560820073/Set+up+a+connection+to+Salesforce#Step-2%3A-Add-a-new-connection)
3. [Authorize the connection](https://appfire.atlassian.net/wiki/spaces/477986818/pages/2560820073/Set+up+a+connection+to+Salesforce#Step-3%3A-Authorize-the-connection)

### Step 1: Select an integration user

1. Go to **Settings** > **Add-ons/Manage apps**.
2. In the sidebar, under *SALESFORCE*, choose **Settings**.
3. On the *Settings* screen, select an **Integration User** for the Salesforce Package.   
This user allows the package to call Jira APIs on the user’s behalf.
4. Click **Save**.

### Step 2: Add a new connection

1. In the sidebar under *CONNECTOR FOR SALESFORCE*, choose **Connections**.
2. <span style="color: #262626">On the </span>*Salesforce Connections*<span style="color: #262626"> screen, click </span>**+Add Connection**<span style="color: #262626">.</span>
3. In the *New Connection *dialog window, enter a **Connection Name**.
4. Click **Add**.  
The connection appears in the **Connection Name** list with the *Status* set to [not authorized].
5. Click **Authorize** under the *Operations* column.

### Step 3: Authorize the connection

1. In the Salesforce Connections window, select **Authorize **for the connection you have just created.

![Salesforce Connections screen with the Authorize option for a connection.](media://f51255f7-3503-44bd-a854-3d6cf9ba708d)

 

You are asked to provide the **Custom Client ID** and **Client Secret**. Keep this window open—you'll get these credentials from Salesforce in the next steps.

#### Configure External Client App Manager

1. In Salesforce, click **Settings **() > **Setup**.
2. In the **Quick Find** box, enter `App Manager`, and select **External Client** **App Manager**.
3. Click **New External Client App**.
  
4. Fill in the *Basic Information *section.
  1. Enter **External Client App Name** (this will display in the External Client App Manager).
  2. Enter the **API Name** to be used when referring to your app from a program.
    There are rules for API names:
    - Must use only letters, numbers, and underscores
    - Must be unique and begin with a letter
    - Can't include spaces, end with an underscore, or contain two consecutive underscores
  3. Enter the **Contact Email** for Salesforce to use if they need to contact you or your support team.  
 (This address isn't shared with Salesforce admins who install the app.)
  4. For the **Distribution State**, select **Local**.
5. Configure *API (Enable OAuth Settings).*
  1. Select the **Enable OAuth** checkbox.
    The App Settings appear.
  2. Provide the **Callback URL**. Enter your Jira instance URL with the callback path.  
The callback URL should start with your Jira instance URL followed by the callback path in this format:  
` [Jira instance URL]rest/com.servicerocket.jira.salesforce/1.0/connection/callback`
  3. For the **OAuth Scopes***,* select the following scopes:
    - **Manage user data via APIs (api)**
    - **Perform requests at any time (refresh_token, offline_access)**
  4. Under** Flow Enablement, **check** Enable Authorization Code and Credentials Flow**.
    
  5. Under **Security,*** *check the following options:
    1. **Require secret for Web Server Flow**
    2. **Require secret for Refresh Token Flow**
    3. **Require Proof Key for Core Exchange (PKCE) extension for Supported Authorization Flows**
    4. **Enable Refresh Token Rotation**
    5. **Limit Idle Refresh Token Time-to-Live (TTL) to 30 Days**
      **Limit Idle Refresh Token TTL to 30 Days** causes a refresh token to expire if it is unused for 30 consecutive days. Each time the token is used within that window, the 30-day clock resets (sliding window). Enabling this setting here affects the Policies step below, which specifies the exact option to select.
6. Click **Create**.
7. Go to the ** Policies **tab and click **Edit**.
  1. In the *App Authorization* section, select the **Expire refresh token if not used for a specific time **and set the** Refresh Token Validity Period **to 30 days.
    Use the same setting here as for the Security refresh token timeout to follow Salesforce [recommendations](https://help.salesforce.com/s/articleView?id=xcloud.eca_limit_idle_refresh_token_ttl.htm&type=5).
  2. Click **Save**.
8. Get your credentials
  1. Go to the *OAuth Settings *section again and** **click **Consumer Key and Secret** to view the credentials.
  2. Verify your identity in Salesforce.
  3. Copy both the **Client ID** and **Client Secret**.

 

#### Complete Authorization in Jira

1. Switch back to Jira.   
If your *Configure Custom OAuth Client *window has closed, reopen it by going to **Salesforce Connections**, then select **Authorize** for your connection.
2. Paste the **Client ID** and **Client secret** into the corresponding fields and click **Next**.
  
3. Select the environment type of your Salesforce instance: **Production** or **Sandbox**, and click **Authorize**.
  
  When the authorization is successful, the *Status *changes to *Authorized* ([authorized]).
4. (Optional) If the authorization is successful, you can import the compact layout fields from Salesforce.  
This pre-populates the objects and fields available through your created connection.
  This step is optional; you can always configure it later.
5. Click **Import** to proceed.

## Next steps 

[Bind a project to a connection](https://appfire.atlassian.net/wiki/spaces/477986818/pages/2560820289)