---
title: "Connect to Salesforce"
canonical: "https://sesame-software-documentation.refined.site/space/bandr/361725963/Connect%20to%20Salesforce"
format: markdown
---
---

### 🔗 Salesforce Connection

Select the authentication method that matches your Salesforce setup.

<details>
<summary>OAuth 2.0 (Recommended)</summary>

> ℹ️ **OAuth 2.0** is the recommended authentication method. It provides secure, token-based access without storing your password, and supports long-term access via refresh tokens.

#### Step 1: Create a Connected App in Salesforce

Before configuring Backup & Recovery, you need to create a Connected App in your Salesforce org. Your Salesforce profile must have the following permissions:

- Create, edit, and delete External Client Apps
- Manage Connected Apps
- View all External Client Apps and their settings
- View Setup and Configuration
- Send Outbound Messages

Navigate to **Setup → External Client Apps → External Client App Manager** and click **New Connected App**. Fill in the required fields:

- **Connected App Name** — e.g., `SesameBackupRecovery`
- **Contact Email** — your admin email address

Enable **OAuth Settings** and configure the following:

- **Callback URL:** `http://<your-hostname>:8080/api/oauth/salesforce/callback`
  Replace `<your-hostname>` with your server's hostname or IP address. For local installations, use `http://localhost:8080/api/oauth/salesforce/callback`.
- **Selected OAuth Scopes:** `full`, `api`, `refresh_token`, `offline_access`, `id`, `profile`, `email`, `address`, `phone`

Click **Save**, then wait 2–10 minutes for the Connected App to propagate. Once ready, click **Manage Consumer Details** to retrieve your **Consumer Key** (Client ID) and **Consumer Secret** (Client Secret).

#### Step 2: Configure initial authorization in Backup & Recovery

In your datasource configuration, set the following fields:

**Logon Information section:**

- **Authentication Type:** `OAuth`
- **Connection URL Mode:** `Production` or `Sandbox`

**OAuth Configuration section:**

- **OAuth Flow Type:** `Initial Authorization`
- **OAuth Client ID:** Your Consumer Key from Step 1
- **OAuth Client Secret:** Your Consumer Secret from Step 1
- **OAuth Redirect URI:** `http://<your-hostname>:8080/api/oauth/salesforce/callback`
- **Salesforce Instance URL:** (Optional) — auto-populated if left blank

Click **Save**, then click **OAuth Login**. Log in to Salesforce and approve access. After approval, Salesforce redirects to your callback URL and displays a success message. Your datasource will be automatically populated with an Authorization Code, Access Token, Refresh Token, and Salesforce Instance URL.

#### Step 3: Switch to Refresh Token flow for ongoing use

After the initial authorization is complete, update the datasource to use the Refresh Token flow so it continues to work without requiring re-authorization.

- In the **OAuth Configuration** section, set **OAuth Flow Type** to `Refresh (Ongoing Use)`
- Click **Save**, then click **Test Connection**

> 📝 **Tip:** In your Salesforce Connected App's token policies, set refresh tokens to *"Refresh token is valid until revoked"* to prevent unexpected re-authorization prompts.
</details>

<details>
<summary>Username / Password</summary>

> ⚠️ **Note:** Salesforce is deprecating the username/password login method. OAuth 2.0 is now the recommended approach for long-term reliability.

| Field | Description |
| --- | --- |
| **Username** | Your Salesforce login username. |
| **Password** | Your Salesforce password. |
| **API Token** | Required to authenticate your session. Generated within Salesforce under *My Settings → Personal → Reset My Security Token*. |
| **Connection URL** (Optional) | Used if connecting to a sandbox or custom domain. Defaults to `login.salesforce.com` if left blank. |
| **API Version** (Optional) | Specifies the Salesforce API version. Defaults to the latest supported version if not provided. |
| **Proxy URL** (Optional) | Needed if routing the connection through a proxy server. |
| **Proxy User** (Optional) | Username for the proxy server, if applicable. |
| **Proxy Password** (Optional) | Password for the proxy server user. |

> ℹ️ If you're unsure how to generate an API Token in Salesforce, check out our [Quick Start Guide](https://sesame-software-documentation.refined.site/space/bandr/377257985/Quick+Start+Guide).
</details>

---

### 🗄️ Destination Database Connection

Enter the details for the **database** where your backups will be stored:

| Field | Description |
| --- | --- |
| **Database Management System** | Choose your DBMS (e.g. PostgreSQL, Oracle, SQL Server). |
| **Database/Catalog** | Name of the target database. |
| **Username** | User credential with write access to the database. |
| **Password** | Associated password for the database user. |
| **JDBC URL** | The full JDBC connection string (e.g., `jdbc:sqlserver://host:port/dbname`). |
| **Schema** | Target schema where tables will be created. |
| **Table Index** (Optional) | Optional naming pattern for your tables. |

---

Once all fields are completed, click **Save** to store your connection details and continue with your backup configuration.

> ✅ **Next Step:** [Authenticating via OAuth ›](#) — configure your B&R application login through an external OAuth provider.