You are here:
Configure OAuth Policies: Manage External Client App OAuth Credentials with AWS Secrets Manager Control
This security integration enables Salesforce to automatically synchronize and store External Client App OAuth consumer secrets directly within a centralized AWS Secrets Manager vault.
Control Name
External Client Apps: Configure OAuth Policies: Manage External Client App OAuth Credentials with AWS Secrets Manager
Recommended Configuration
Manage External Client App OAuth Credentials with AWS Secrets Manager.
Control Overview
This security integration enables Salesforce to automatically synchronize and store External Client App OAuth consumer secrets directly within a centralized AWS Secrets Manager vault rather than maintaining them as static metadata within the Salesforce platform.
Security Risk If Not Configured
Weak external management or decentralized storage of OAuth secrets leads to a single-point breach risk where a compromise of unsecured credentials exposes all integrated backend services to unauthorized access.
Threat Scenarios
An attacker gains access to a plaintext configuration file or an unprotected administrative interface containing static secrets and uses those credentials to impersonate the external client application across multiple production environments.
Estimated CVSS Score Range
High (7.0–8.9).
Risk Impact Considerations
Failure to use a hardware-backed or managed vault results in persistent credential exposure, as compromised secrets often remain valid for extended periods without the benefit of automated rotation or centralized audit logging.
Higher Risk When
When the same OAuth secret is manually shared across multiple distributed cloud environments or stored in version control systems without cryptographic protection.
Low Risk When
If the company already uses a robust, identity-based access management policy within AWS that restricts secret retrieval to specific verified VPC endpoints and execution roles.
Business and Integration Considerations
Implementing this control requires an active AWS account and the configuration of a named credential in Salesforce to establish a secure mutual authentication path between the two cloud platforms.
Recommended Remediation
Configure the External Client App to use AWS Secrets Manager for credential storage by defining the secret Amazon Resource Name and establishing the necessary cross-cloud authorization policies.
Security Health Review Guidance
Security Health Review identifies the use of externalized secret management as a strongly recommended standard for high-assurance integrations to make sure that sensitive authentication artifacts are protected by enterprise-grade vaulting and automated rotation policies.
