API Integration Security Patterns

Overview

API integrations are a major risk surface in Salesforce programs. This guide captures practical controls for API authentication, connected app governance, token management, and monitoring.

Consensus Best Practices

Core Security Patterns

Pattern 1: Least-Privilege Integration Identity

Pattern 2: Connected App Governance

Pattern 3: Outbound Callout Hardening

Pattern 4: Token and Session Hygiene

Pattern 5: Data Egress Controls

API Selection Guidance

Monitoring Checklist

Sources Used