Connect Robin with Salesforce by granting Atera access to your environment through an External Client App using OAuth 2.0 authentication. Robin can act on your behalf to handle key tasks like managing user access and resolving common Salesforce account issues.
Before you begin
Before setting up the integration, make sure you already have:
- An active Atera account with access to Robin.
- An active Salesforce account with Customize Application permission.
-
A dedicated Salesforce user for Robin to run as, with the Salesforce Integration user license and the Minimum Access - API Only Integrations profile. Robin runs using this user, and only gets the access that profile allows.
Connect to Salesforce
To create and configure an External Client App in Salesforce:
1. Log in to your Salesforce organization account.
2. Click the Quick Settings gear icon and click Open Advanced Setup. You will be redirected to the Setup page.
3. From the left-side panel, go to Apps > External Client Apps > External Client Apps Manager.
4. Click New External Client App.
5. Fill in the Basic Information fields: External Client App Name, API Name (auto-populated), Contact Email, and Distribution State set to Local.
6. In the API (Enable OAuth Settings) section:
- Check the Enable OAuth box.
- Under App Settings:
- Callback URL: Enter the following URL: https://app.atera.com/proxy/integrationssalesforce/management/callback
-
OAuth Scopes: Select the following scopes from the Available OAuth Scopes list and click the top arrow to move them to the Selected OAuth Scopes list:
- Perform requests at any time (refresh_token, offline_access) — Maintains the connection without requiring re-authentication when the session expires.
- Manage user data via APIs (api) — Allows Robin to interact with user-related data or services within Salesforce.
- Under Flow Enablement, check the following boxes:
- Enable Authorization Code and Credential Flow
- Enable Device Flow
7. Click Create. You will be redirected to the details page of your new External Client App.
8. Click Edit.
9. Open the Policies tab and expand OAuth Policies
10. Under OAuth Flows and External Client App Enhancements, check Enable Client Credentials Flow, then in Run As (Username) enter the username of your Salesforce integration useer.
11. Click Save.
12. In the Settings tab, under OAuth Settings, click on Consumer Key and Secret. It will take you to the Consumer Details page.
13. Copy the Consumer Key and Consumer Secret and store them in a secure location.
14. From your Atera navigation panel, go to Robin > Integrations > Product integrations. The Product integrations page will appear.
15. Open the Discover tab and click the Salesforce card. The Salesforce window appears.
16. Enter your Consumer key and Consumer Secret, turn on Use client credentials flow, and enter your My Domain URL. To find it, go to Salesforce Setup, search for My Domain, and copy your current My Domain URL. Then click Connect.
17. Robin will connects straight away since ntegration runs as your Run As user, no Salesforce approval window appears.
Congratulations, Robin is now connected to Salesforce!
Salesforce Approval Fails or Shows an Error
Common causes:
- The External Client App is misconfigured (callback URL, OAuth scopes, or OAuth settings).
- The Salesforce user does not have sufficient permissions.
- The app's Run As (Username) is empty, or the integration user it points to is inactive.
- The My Domain URL entered in Atera is missing or does not match your Salesforce org.
Resolution:
- Verify your External Client App OAuth configuration.
- Confirm the correct callback URL is configured.
- Ensure required OAuth scopes are enabled.
- In the app's Policies tab, confirm Enable Client Credentials Flow is checked and Run As (Username) holds an active integration user.
- Use a more privileged Salesforce user if necessary.