Loading
시스템 관리자에 대한 피싱 방지 MFA 및 전 직원사용자 MFA 적용 안내 더 많이 읽기

Troubleshooting and Managing the Quip Connected App in Salesforce

게시 일자: Aug 12, 2026
상세 설명

The Quip Connected App is a Salesforce connected app installed as part of the Quip Setup Starter managed package. It manages the OAuth authentication that allows Salesforce users to connect their accounts to Quip and enables the Quip Document Component, Live Data Mentions, and Flow actions to function. This article explains how to locate and verify the connected app configuration and how to resolve common issues.

솔루션

This article explains how to find and verify the Quip Connected App configuration in Salesforce, and how to resolve the most common access and authentication issues.

Finding the Quip Connected App

  1. In Salesforce Setup, search for App Manager in the Quick Find box.
  2. Find the connected app named Quip in the list.
  3. Click the dropdown arrow next to Quip and select View to see the current configuration.

Verifying the Connected App Configuration

Check the following settings on the Quip Connected App:

  • Permitted Users: Should be set to All users may self-authorize so that any Salesforce user with the Quip User permission set can connect their account. If set to Admin approved users are pre-authorized, only users on the approved list can connect.
  • OAuth Scopes: The app must have at minimum Access and manage your data (api) and Perform requests on your behalf at any time (refresh_token, offline_access).
  • IP Relaxation: Depending on your org's IP restrictions, you may need to set this to Relax IP restrictions so the Quip integration can authenticate from Quip's servers.

Example: Users report they cannot complete the Salesforce-Quip OAuth connection — they click Connect but receive an error. The admin checks the connected app and finds Permitted Users is set to Admin approved only. Changing it to All users may self-authorize immediately resolves the issue.

Avoiding SAML Naming Conflicts

If you configure SAML with Salesforce as the Identity Provider and Quip as the Service Provider, use a different Name and API Name than "Quip" for that SAML connected app — the Quip integration and Quip Connected App need to keep the API name "Quip" to function correctly.

  • We recommend a naming convention such as Quip SAML or Quip SSO for the SAML connected app.
  • This only applies to Quip sites configured to Salesforce using SAML/SSO. If your Quip site and Salesforce org are connected through Okta, ADFS, or another identity provider, this does not apply.
  • More information about SAML is available here.

Revoking and Re-Establishing User Connections

If a specific user's Quip-Salesforce connection breaks, they can revoke and reconnect it. Note that an admin cannot complete these steps on a user's behalf — the user must do this themselves between their Quip and Salesforce accounts.

  1. In Salesforce, go to the user's Personal Settings > Connected Apps OAuth Usage, and click Revoke next to Quip. Admins can also revoke a specific user from the Authenticated Quip Connected App user list.
  2. Log in to Quip.com, click the Quip profile icon, select Salesforce, and choose Disconnect from the connected org. Keep the Quip tab open.
  3. Log in to Salesforce, click the profile icon, then Settings, then Authentication Settings for External Systems, and delete the Quip entry.
  4. Refresh the Salesforce page. A blue banner should appear reading "Take the Last Step" — click it and complete the authentication flow.
  5. If the banner doesn't appear or doesn't work, open the Files tab in Salesforce, select Quip, and choose Connect to Quip to reconnect.

Regenerating the Consumer Key and Secret

If the connected app's consumer key or secret needs to be updated (for example, after a security incident), go to App Manager > Quip > Edit in Setup, then click Manage Consumer Details to view or regenerate the credentials. After regenerating, update the Quip Auth Provider in Setup with the new values, then re-validate and sync the Quip External Data Source.

Common Access and Permission Issues

  • User has no Quip Permission Set: Confirm the user is assigned the Quip Permission Set — without it they won't see the connection banner or be able to use Quip features.
  • API key missing scopes: If the API key used to configure the integration only has the Admin checkboxes selected, create a new API key in the Quip Admin Console (under Settings, Integrations) with all required checkboxes enabled, and update the Quip Auth Provider with the new key and secret. We don't recommend reusing the same API key across more than one integration or org — reuse can cause errors.
  • Integration User shown in OAuth Usage: Seeing a Cloud user/username authenticated against the Quip Connected App is expected — Salesforce creates an Integration User for this purpose. Leave it connected and authenticated; deactivating or revoking it can break the integration and, in some orgs, require a full reconfiguration. See this Integration User guide for more detail.
  • Modified Admin Role permissions: If your org uses a modified Admin Role, review the permission changes Salesforce has made to accessing and installing the Quip Connected App, described here. Missing permissions can cause errors accessing the Quip Connected App. See also this Quip permissions guide.

If you haven't yet installed the Quip integration in Salesforce, see these setup instructions.

Knowledge 기사 번호

005225367

 
로드 중
Salesforce Help | Article