Authorization: Integration User

To access the Agentforce IT Service Configuration Management Database (CMDB) GraphQL API, you must authenticate using an Integration User via a standard OAuth 2.0 flow.

You must have administrator access to your Salesforce org to create Integration Users and Connected Apps.

  1. Log in to your Salesforce org as an administrator.

  2. Create a dedicated User record with the Salesforce Integration User License.

  3. Assign the Integration User to a Permission Set that includes at least one of the following permissions. These permissions determine what data you can access via the API:

    • ItsrvcCnfgItmTypMgr
    • ItsrvcCnfgItmOwner
    • ItsrvcCnfgItmRead
  4. Create a Connected App (also known as an External Client App) and retrieve your OAuth credentials (Client ID and Client Secret). For detailed instructions, see Authorization Through Connected Apps and OAuth 2.0.

  5. Generate a Bearer Token by exchanging your client credentials for an access token.

    Send a POST request to the OAuth token endpoint:

    1POST /services/oauth2/token HTTP/1.1
    2Host: your-instance.salesforce.com
    3Content-Type: application/x-www-form-urlencoded
    4
    5grant_type=client_credentials&
    6client_id=<YOUR_CLIENT_ID>&
    7client_secret=<YOUR_CLIENT_SECRET>

    The response includes an access token:

    1{
    2  "access_token": "00D...",
    3  "instance_url": "https://your-instance.salesforce.com",
    4  "id": "...",
    5  "token_type": "Bearer",
    6  ...
    7}

    Use the access_token value in the Authorization header of your CMDB GraphQL requests.

See Also