Skip to main content

Hi everyone,

We are preparing an external API / web application integration for our AppExchange Security Review. The review team will need to test our API endpoints from their automated scanning suites and dynamic networks.

Our main operational blocker right now is MFA and Device Activation (OTP). Because our team does not have personnel available on standby 24/7 to instantly provide multi-factor authentication access codes or email OTP tokens to the reviewers, we need an entirely hands-off authentication architecture for our test environment.

Given Salesforce’s strict platform enforcements restricting traditional UI MFA bypass permissions, what is the current accepted practice for API apps?

My Questions:

  • If we provision a dedicated Salesforce Integration User license (which uses API-only tokens/OAuth instead of interactive UI login), does the Security Review team's automated testing suite natively support this without triggering an MFA or Device Activation challenge?
  • If the review suite requires standard user credentials that trigger an unexpected email OTP, how are partners managing this asynchronously without a 24/7 live operations team to hand over codes?

We want to make sure we architect our authentication flow correctly so that the submission doesn't fail pre-queue validation due to a missed MFA prompt. Any advice from recent submitters would be huge. 

 

#Appexchage Apps

 

 

#Security Review  #Agentforce

1 Antwort
  1. Heute 05:44

    For an AppExchange Security Review, I’d avoid designing around the assumption that an API-only user automatically bypasses every authentication control. The safer approach is to confirm the current review-team requirements for integration credentials and test the exact OAuth/API flow in the submitted environment beforehand. If automated scanners require interactive authentication, Salesforce Partner Support or the Security Review team should clarify the supported testing arrangement rather than relying on manual OTP handling.  Visit here for more information.

0/9000