The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Salesforce Named Credentials let an API callout refer to a configured endpoint while keeping authentication settings separate from Apex code. The current architecture pairs a Named Credential with an External Credential, then grants access through configured principals and Salesforce permissions. That separation makes integrations easier to reuse and manage without embedding endpoint or authentication details in each callout.
What Named Credentials do in a Salesforce integration
A Named Credential specifies the callout endpoint and transport. An External Credential defines the authentication protocol and principals Salesforce uses to authenticate and authorize against the remote service. Apex can call the Named Credential by name instead of embedding the endpoint and authentication configuration in the callout.
As an Amazon Associate I earn from qualifying purchases.
Salesforce introduced its extensible Named Credentials architecture in Winter ’23 and recommends it. Legacy Named Credentials are deprecated, but Salesforce has not stated a discontinuation date on the cited documentation page. The current model also supports External Data Sources and External Services, and credentials can use custom headers for additional use cases.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteHow the pieces fit together
- Named Credential: the remote endpoint and transport configuration used by a callout.
- External Credential: the authentication protocol and principal configuration.
- Principal: the identity used for authentication, such as a shared integration identity or an individual user.
- Permission assignment: associates eligible Salesforce users with the principal through permission sets, profiles, or permission set groups.
- User External Credential: encrypted token storage. Salesforce documents that these records are not exposed through SOQL, Apex, or APIs.
This separation gives administrators a central place to manage endpoint and authentication configuration, while code refers to a named configuration rather than carrying those details itself. Salesforce’s Get Started with Named Credentials documentation describes a named credential as specifying a callout endpoint URL and its required authentication parameters in one definition.
#1 Best Overall
Choose the identity the remote service should see
The key design choice is whether the remote service should see one shared integration identity or the identity of each Salesforce user. Neither option is universally more secure; the right fit depends on how authorization is meant to work in both systems.
| Design | Identity presented to remote service | Authentication and access implications |
|---|---|---|
| Named principal | A shared identity configured for the integration. | Users who have access to the principal use the common integration identity. Provisioning and revocation should reflect which Salesforce users are allowed to invoke that shared access. |
| Per-user principal | The current Salesforce user’s identity and token. | Each user must authenticate before the integration works for them. Salesforce automatically incorporates the current user’s context and passes the access token in the appropriate header. |
Use a named principal when the remote application is intended to authorize calls as a common service account. Choose per-user authentication when the remote system must enforce each person’s own identity and permissions. In either case, decide how users receive access, how credentials are refreshed, and how access is revoked according to the integration’s requirements.
Rank #2
Set up an OAuth Named Credential
Salesforce’s documented flow establishes the authentication configuration, connects it to an endpoint, grants access, and completes authentication. An external auth identity provider may be needed for the selected OAuth browser flow.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Configure an external auth identity provider if the flow requires one. Use the provider configuration needed for the OAuth browser flow you selected.
- Create an External Credential. Select the authentication protocol and configure the principal or principals for the integration.
- Create a Named Credential. Enter the endpoint and link the credential to the External Credential.
- Grant principal access. Assign the relevant permission set, profile, or permission set group so the intended Salesforce users can use the principal.
- Complete authentication. Authenticate the integration or, for per-user OAuth, have each eligible user authenticate individually.
- Use the Named Credential in the callout. Reference its name in the callout rather than hard-coding the endpoint and authentication configuration in Apex.
Salesforce’s Create an OAuth Named Credential and Use the Named Credential in a Callout examples describe this sequence. In the example’s programmatic status check, a credential that has not been configured is reported as “Not Configured.”
Package and deploy credentials deliberately
For a managed second-generation package (2GP), include the credential metadata and the permissions that let packaged code use it. Named Credentials are not added to packages automatically, so include one whenever packaged Apex or an external data source refers to it. A subscriber may also supply a credential with the expected name, subject to the package’s namespace allowance rules.
Include in the package
- The Named Credential.
- The External Credential.
- The permission set that grants access to the required principal.
- An external auth identity provider when required for the OAuth browser flow.
Complete in the target org
Tokens and certificates cannot be packaged. Populate them after installation through the Salesforce UI or Connect REST API, following the authentication flow you selected. Validate that the target org has the required principal permissions and completed authentication before relying on callouts.
Rank #4
Decide who controls packaged settings
Since February 2026, packaged Named Credentials default to developer control. Subscriber control can be useful when each customer uses a different service subdomain or an on-premises gateway. Choose based on who needs to manage endpoint and authentication settings after installation, rather than assuming that one control model fits every deployment. See Salesforce’s Package Named Credentials and Populate External Credential Principals documentation.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesProtect callouts when changing managed credentials
Salesforce applies a safeguard when managed-package code programmatically updates a Named Credential: callouts are disabled to prevent an authenticated connection from being silently redirected. After reviewing the change, a subscriber administrator must turn callouts back on. Treat that re-enablement as an operational review step, not an automatic part of deployment. Salesforce documents the behavior in Update or Delete an OAuth Named Credential.
Quick Recap
Best Value
Implementation checklist
- Use the current Named Credential and External Credential model rather than starting a new integration on the deprecated legacy architecture.
- Choose a named principal or per-user identity according to the identity and permissions the remote service must enforce.
- Grant principal access only to the intended Salesforce users through permission assignments.
- For packages, include every referenced credential and required permission metadata, then plan separately for target-org tokens and certificates.
- Choose developer or subscriber control with customer-specific endpoints and on-premises gateways in mind.
- After a managed-package code update disables callouts, have an administrator review the change before restoring them.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




