Reference

Authentication JWT Bearer (External Client App)


Description

No description available [API reference]

Instructions

JWT Bearer Flow with an External Client App (current Salesforce recommendation for JDBC). No refresh-token dance; you still register the callback URL so the app is valid.

  1. Create an External Client App in Salesforce Setup. Enable OAuth and JWT Bearer.
  2. Callback URL must be exactly https://zappysys.com/oauth (do not use localhost or another capture URL).
  3. Upload or generate a certificate. Download the private key as PEM (-----BEGIN PRIVATE KEY-----).
  4. Copy the Consumer Key (Client ID).
  5. Paste Client ID, integration username, and the full PEM into this profile. Do not check a private key into source control.
  6. Finish the wizard. Then click Test Connection on the DSN Main UI (the wizard does not run Test Connection).
  7. Done. You can query from C#, Python, PowerShell, and ODBC apps.

Parameters

Parameter Required Default value Options
Name: DriverFilePaths

Label: JDBC driver file(s)

Filled by the wizard after download. Separate multiple JARs with a semicolon (e.g. C:\ZappySys\Jdbc\MyConnector\driver.jar).
YES C:\ZappySys\Jdbc\Salesforce Data Cloud (Data 360)\jdbc-0.29.0-shaded.jar
Name: LoginHost

Label: Login host

Salesforce login host (e.g. login.salesforce.com).
YES login.salesforce.com
Name: UserName

Label: User name

Integration username for JWT Bearer.
YES
Name: clientId

Label: Client ID (Consumer Key)

Consumer Key from the External Client App.
YES
Name: privateKey

Label: Private key (PEM)

Paste the PEM private key text for JWT Bearer (e.g. -----BEGIN PRIVATE KEY-----). This is not a file path. Never ship a key in XML or source control.
YES
Name: DriverClass

Label: Driver class

Optional. Leave blank to auto-detect from the JAR unless SPI is ambiguous (e.g. com.salesforce.datacloud.jdbc.DataCloudJDBCDriver).
com.salesforce.datacloud.jdbc.DataCloudJDBCDriver
Name: dataspace

Label: Data space

Data Cloud data space. Default is default.
default