October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Salesforce Named Credentials: Key Facts for API Integrations

Salesforce Named Credentials separate API endpoints from authentication configuration. Learn how principals, OAuth identity choices, packaging, and change safeguards fit together.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Salesforce Named Credentials let an API callout refer to a configured endpoint while keeping authentication settings separate from Apex code. The current architecture pairs a Named Credential with an External Credential, then grants access through configured principals and Salesforce permissions. That separation makes integrations easier to reuse and manage without embedding endpoint or authentication details in each callout.

What Named Credentials do in a Salesforce integration

A Named Credential specifies the callout endpoint and transport. An External Credential defines the authentication protocol and principals Salesforce uses to authenticate and authorize against the remote service. Apex can call the Named Credential by name instead of embedding the endpoint and authentication configuration in the callout.

As an Amazon Associate I earn from qualifying purchases.

Salesforce introduced its extensible Named Credentials architecture in Winter ’23 and recommends it. Legacy Named Credentials are deprecated, but Salesforce has not stated a discontinuation date on the cited documentation page. The current model also supports External Data Sources and External Services, and credentials can use custom headers for additional use cases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the pieces fit together

  • Named Credential: the remote endpoint and transport configuration used by a callout.
  • External Credential: the authentication protocol and principal configuration.
  • Principal: the identity used for authentication, such as a shared integration identity or an individual user.
  • Permission assignment: associates eligible Salesforce users with the principal through permission sets, profiles, or permission set groups.
  • User External Credential: encrypted token storage. Salesforce documents that these records are not exposed through SOQL, Apex, or APIs.

This separation gives administrators a central place to manage endpoint and authentication configuration, while code refers to a named configuration rather than carrying those details itself. Salesforce’s Get Started with Named Credentials documentation describes a named credential as specifying a callout endpoint URL and its required authentication parameters in one definition.

Choose the identity the remote service should see

The key design choice is whether the remote service should see one shared integration identity or the identity of each Salesforce user. Neither option is universally more secure; the right fit depends on how authorization is meant to work in both systems.

Design Identity presented to remote service Authentication and access implications
Named principal A shared identity configured for the integration. Users who have access to the principal use the common integration identity. Provisioning and revocation should reflect which Salesforce users are allowed to invoke that shared access.
Per-user principal The current Salesforce user’s identity and token. Each user must authenticate before the integration works for them. Salesforce automatically incorporates the current user’s context and passes the access token in the appropriate header.

Use a named principal when the remote application is intended to authorize calls as a common service account. Choose per-user authentication when the remote system must enforce each person’s own identity and permissions. In either case, decide how users receive access, how credentials are refreshed, and how access is revoked according to the integration’s requirements.

Set up an OAuth Named Credential

Salesforce’s documented flow establishes the authentication configuration, connects it to an endpoint, grants access, and completes authentication. An external auth identity provider may be needed for the selected OAuth browser flow.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Configure an external auth identity provider if the flow requires one. Use the provider configuration needed for the OAuth browser flow you selected.
  2. Create an External Credential. Select the authentication protocol and configure the principal or principals for the integration.
  3. Create a Named Credential. Enter the endpoint and link the credential to the External Credential.
  4. Grant principal access. Assign the relevant permission set, profile, or permission set group so the intended Salesforce users can use the principal.
  5. Complete authentication. Authenticate the integration or, for per-user OAuth, have each eligible user authenticate individually.
  6. Use the Named Credential in the callout. Reference its name in the callout rather than hard-coding the endpoint and authentication configuration in Apex.

Salesforce’s Create an OAuth Named Credential and Use the Named Credential in a Callout examples describe this sequence. In the example’s programmatic status check, a credential that has not been configured is reported as “Not Configured.”

Package and deploy credentials deliberately

For a managed second-generation package (2GP), include the credential metadata and the permissions that let packaged code use it. Named Credentials are not added to packages automatically, so include one whenever packaged Apex or an external data source refers to it. A subscriber may also supply a credential with the expected name, subject to the package’s namespace allowance rules.

Include in the package

  • The Named Credential.
  • The External Credential.
  • The permission set that grants access to the required principal.
  • An external auth identity provider when required for the OAuth browser flow.

Complete in the target org

Tokens and certificates cannot be packaged. Populate them after installation through the Salesforce UI or Connect REST API, following the authentication flow you selected. Validate that the target org has the required principal permissions and completed authentication before relying on callouts.

Decide who controls packaged settings

Since February 2026, packaged Named Credentials default to developer control. Subscriber control can be useful when each customer uses a different service subdomain or an on-premises gateway. Choose based on who needs to manage endpoint and authentication settings after installation, rather than assuming that one control model fits every deployment. See Salesforce’s Package Named Credentials and Populate External Credential Principals documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect callouts when changing managed credentials

Salesforce applies a safeguard when managed-package code programmatically updates a Named Credential: callouts are disabled to prevent an authenticated connection from being silently redirected. After reviewing the change, a subscriber administrator must turn callouts back on. Treat that re-enablement as an operational review step, not an automatic part of deployment. Salesforce documents the behavior in Update or Delete an OAuth Named Credential.

Implementation checklist

  • Use the current Named Credential and External Credential model rather than starting a new integration on the deprecated legacy architecture.
  • Choose a named principal or per-user identity according to the identity and permissions the remote service must enforce.
  • Grant principal access only to the intended Salesforce users through permission assignments.
  • For packages, include every referenced credential and required permission metadata, then plan separately for target-org tokens and certificates.
  • Choose developer or subscriber control with customer-specific endpoints and on-premises gateways in mind.
  • After a managed-package code update disables callouts, have an administrator review the change before restoring them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.