Connected Apps (CAs) and External Client Apps (ECAs) enable third-party applications to integrate with Salesforce using Salesforce APIs and standard security protocols, such as SAML, OAuth, and OpenID Connect. CAs and ECAs use these protocols to authenticate, authorize, and provide single sign-on (SSO) for third-party applications.
The security review of managed packages examines the configuration of the packaged Connected App or ECA and every integration the application uses - web applications, REST APIs, mobile apps, browser plugins, and desktop apps are all in scope.
This article answers: what does Salesforce check during an AppExchange security review of a package's Connected Apps and ECAs, and what should be included in the submission?
New integrations must use ECAs instead of Connected Apps. CAs and ECAs should be packaged for distribution on AppExchange. There are use cases where packaging is mandatory, shown in the table below. In other cases an ECA may need to be created on the subscriber org after installation — if that applies, document the use case in your submission.
Don't delete existing Connected Apps or ECAs from the org, or remove them from the package, before evaluating the impact of that action. If you have packaging questions, reach out to customer support.
| Use Case | Condition | Packaging Required? |
|---|---|---|
| Authorization code flow (Web server flow) | When callback URLs are controlled by the ISV (Independent Software Vendor) Partner | Yes |
| Client credentials (Server-to-Server) flow | Use when using the ISV's client ID and secret is acceptable | Yes |
| JWT Bearer (Server-to-Server) flow | Certificate and private key owned by the ISV partner. A common use case is generating OAuth tokens instead of using a session ID to invoke the metadata API | Yes |
| Canvas app integration | Packaging is mandatory, no specific condition required | Yes |
Follow these practices for your app's OAuth configuration and coding:
Robust security measures must protect the secrets used in CA/ECA use cases — including secure packaging, safeguarding the client key, client secret, encryption keys, and certificates within web applications, and securely storing auth and refresh tokens.
Find more information in the OWASP Secrets Management Cheat Sheet.
Robust security measures are essential for the integrity of these critical organizational environments.
Report any suspicious activity or security incident affecting your applications or their customer secrets immediately by emailing security@salesforce.com for investigation.
005318040

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.