Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Agentforce Contact Center
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Configuring Single Sign-On (SSO) with Amazon Connect

          Configuring Single Sign-On (SSO) with Amazon Connect

          Set up single sign-on between Salesforce and Amazon to allow users to log in to Salesforce once and then be automatically logged in to Amazon using the same credentials.

          Required Editions

          This article applies to:

          • Salesforce Voice with Amazon Connect
          • Salesforce Voice with Partner Telephony from Amazon Connect
          View supported editions.

          For Salesforce Voice with Amazon Connect or Salesforce Voice with Partner Telephony from Amazon Connect each Salesforce Voice contact center comes with these default behaviors:

          • One Amazon Connect user is created for each Salesforce user (rep or supervisor) that you add to the Salesforce Voice contact center.
          • Salesforce Voice manages users in Salesforce orgs only. Salesforce doesn’t manage users in Amazon Connect. For example, deactivating a user in Salesforce doesn’t deactivate them from Amazon Connect.

          For each contact center you create, Salesforce creates an Amazon Connect instance with the following default SSO configuration:

          • Amazon is the service provider.
          • Salesforce is the identity provider (IdP). As the IdP, Salesforce authenticates users and provides credentials to Amazon, the requesting service provider. Salesforce Voice references Salesforce users as the source of truth for identities.
          • Salesforce Voice and Amazon Connect support SAML 2.0-based authentication.
          • Salesforce automatically adds the Salesforce Single Sign-On external client app to the Salesforce Voice permission set. Salesforce assigns the permission set to all users selected as contact center admins when the center is created. Any logged in Salesforce user with the Salesforce Voice permission set is automatically logged into the contact center’s associated Amazon Connect instance.
          Important
          Important For contact centers created before the Summer '26 release, Salesforce uses connected apps for single sign-on (SSO). For these older contact centers, two Salesforce connected apps were automatically created when you created the contact center in Voice. The Single Sign-On Connected App and REST API OAuth Connected App were created and assigned a connected app permission set to your contact center admins.

          Use Cases

          This section lists some possible SSO integrations for Salesforce Voice with Amazon Connect and Salesforce Voice with Partner Telephony from Amazon Connect.

          Use only Salesforce as the identity provider for Amazon Connect
          Use Case Supported?
          Sign in to Salesforce and then use Salesforce Voice with the Omni-Channel softphone. Yes.
          Sign in to Salesforce and then use the Amazon Connect CCP softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          Use the Omni-Channel or Amazon Connect CCP softphone without signing in to Salesforce first. No.
          Use Salesforce plus a third party as identity providers for Amazon Connect

          The user directory is maintained through the third party identity provider.

          Use Case Supported?
          Sign in to Salesforce and then use Salesforce Voice with the Omni-Channel softphone. Yes.
          Sign in to Salesforce and then use the Amazon Connect CCP softphone. Yes.
          Sign in via the third-party IdP and then use the Amazon Connect CCP softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          Sign in via the third-party IdP and then use Salesforce Voice with the Omni-Channel softphone. No.
          Use a third-party identity provider for Amazon Connect
          Use Case Supported?
          Sign in to Salesforce and then use Salesforce Voice with the Omni-Channel softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          Sign in to Salesforce and then use the Amazon Connect CCP softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          Sign in via the third-party IdP and then use the Amazon Connect CCP softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          Sign in via the third-party IdP and then use Salesforce Voice with the Omni-Channel softphone. Yes with some additional configuration. Contact Salesforce Customer Support.
          • Maintain Your Managed External Client App
            When you create a contact center, Salesforce automatically generates a managed external client app (ECA) to handle your SAML single sign-on (SSO) authentication. Because Salesforce manages this external client app as part of your contact center provisioning, you can’t access or edit it from the External Client App Manager in Setup. Instead, manage all settings and policies for this app from your contact center settings.
           
          Loading
          Salesforce Help | Article