Authorization: User Sign-In

To access the Agentforce IT Service Configuration Management Database (CMDB) GraphQL API, you must authenticate using an OAuth 2.0 Authorization Code flow with user sign-in, so that API calls run under the signed-in user’s identity.

You must have administrator access to your Salesforce org to create Connected Apps.

  1. Log in to your Salesforce org as an administrator.

  2. Create a Connected App (also known as an External Client App) and retrieve your OAuth credentials (Client ID and Client Secret). For detailed instructions, see Authorization Through Connected Apps and OAuth 2.0.

  3. Obtain the authorization code from the Salesforce authorization URL.

    Execute the following request to receive an authorization code at your callback URL:

    Authorization request:

    1POST /services/oauth2/authorize
    2Host: your-instance.salesforce.com
    3Content-Type: application/x-www-form-urlencoded
    4
    5response_type=code
    6client_id=<Your Client ID>
    7redirect_uri=https%3A%2F%2Flocalhost%2F
    8scope=api%20sfap_api

    Use the redirect URI from your Connected App.

  4. Exchange your authorization code for an access token.

    Submit a POST request to the token endpoint using the code from the previous step:

    1POST /services/oauth2/token
    2Host: your-instance.salesforce.com
    3Content-Type: application/x-www-form-urlencoded
    4
    5grant_type=authorization_code&
    6code=<received from step 3>&
    7redirect_uri=http://localhost/&
    8client_id=<YOUR_CLIENT_ID>&
    9client_secret=<YOUR_CLIENT_SECRET>

    Use the access_token you received in the Authorization header for your CMDB GraphQL requests.