Shivanath Devinarayanan · Updated
On this page
On-behalf-of is the difference between a shared robot user and a reviewable actor. Every hop goes through the gateway. Tokens narrow: audience is the next component only. Client IDs stay masked on this page.
Salesforce Token Exchange (a connected or external client app plus a token-exchange handler) is the path when Salesforce is the authorization server. CIBA is the path when a sensitive action needs out-of-band approval. In-task authorization code plus PKCE is the path when a downstream agent trusts a different IdP and returns an auth challenge. The wrapper does not invent token exchange inside the Mule app. The gateway does OBO.
- User Token note The person who asked. Their identity is the start of the trail, not a shared robot account.
- Surface Token note Slack, email, web, or a scheduled job. Audience is the broker. The surface does not keep a standing token into Salesforce.
- Broker Token note Routes the task. Audience is the gateway. The broker does not mint an Agentforce session as itself.
- Gateway Token note Does on-behalf-of. Audience is the next component only: Agentforce, an MCP server, or a peer. Client IDs stay masked on this page.
- Agentforce or MCP Token note Acts as the named person, or as the machine user when per-user identity is not required. That default is stated, not hidden.
Hops, with a token note
- 1. User. The person who asked. Their identity is the start of the trail, not a shared robot account.
- 2. Surface. Slack, email, web, or a scheduled job. Audience is the broker. The surface does not keep a standing token into Salesforce.
- 3. Broker. Routes the task. Audience is the gateway. The broker does not mint an Agentforce session as itself.
- 4. Gateway. Does on-behalf-of. Audience is the next component only: Agentforce, an MCP server, or a peer. Client IDs stay masked on this page.
- 5. Agentforce or MCP. Acts as the named person, or as the machine user when per-user identity is not required. That default is stated, not hidden.
Machine path stays named
Client-credentials remains the default when per-user identity is not required. That fact is stated here, not treated as a secret. The Run As user is still a name on the record. Setup of that app is on Agentforce setup in the org .
Restricted records need session isolation and on-behalf-of Salesforce permission sets. That page is isolation for restricted records . Wrapping the runtime as a peer is Agentforce as a peer .
Also in this file: Home · About · Services · Portfolio · Success Stories · Writing · Events · Contact · Media kit · Privacy Policy