Salesforce Enable JWT Authentication for the ActiFi Connected App and API User

Salesforce Enable JWT Authentication for the ActiFi Connected App and API User

Introduction
This guide provides step-by-step instructions for Salesforce administrators to update the SuccessPro Connected App's settings, enabling the OAuth 2.0 JWT bearer flow for the API user configured to integrate with SuccessPro.
Prerequisites:
  • You must have Salesforce Administrator permissions.
  • You must have the public key certificate file provided by the ActiFi Development team.Ex: [tenant-name]_salesforce_api_integration.crt

Part 1: Configure the SuccessPro Connected App

Step 1: Navigate to App Manager
    Log in to your Salesforce account.
    Click the gear icon (Setup) in the top-right corner and select Setup.
    In the "Quick Find" box on the left, type App Manager and click on it when it appears.
Step 2: Locate and Edit the SuccessPro Connected App
    In the list of applications, find the “SuccessPro Connected App” that needs to be updated. Note: In older installations, this Connected App may be named "Roadmap".
    Click the dropdown arrow on the far right of that app's row and select Edit.
Step 3: Enable Digital Signatures & Upload Certificate
    On the main edit page for the Connected App, scroll down to the API (Enable OAuth Settings) section.
    Check the box labeled Use digital signatures.
    Once the box is checked, a Choose File button will appear. Click it.
    Select the public certificate file (.crt) that was provided by the ActiFi development team.Note: If downloading the .crt file from a browser, you may get a warning saying the file could be harmful. This file is safe to download if provided via link from your ActiFi contact.
Step 4: Assign OAuth Scopes
    In the Selected OAuth Scopes list, ensure the following 2 scopes are included. If they are not, select them from the "Available OAuth Scopes" and click the "Add" arrow.
  • Access and manage your data (api) OR Manage user data via APIs (api)
  • Perform requests on your behalf at any time (refresh_token, offline_access)
Step 5: Save Your Changes
    Scroll to the bottom of the page and click the Save button.
    A confirmation message will appear noting that changes can take a few minutes to take effect. Click Continue.
Step 6: Retrieve the Connected App Consumer Key
    From the App Manager list of applications, select View from the dropdown arrow for the SuccessPro Connected App.
    Click the Manage Consumer Details button on the Consumer Key and Secret row.
    Copy the Consumer Key and send this key back to your ActiFi contact.

Part 2: Create and Configure a Permission Set

Creating a dedicated permission set is a security best practice, as it allows you to grant access to the Connected App without altering a user's broader profile permissions.
Step 7: Create a New Permission Set
    While in Setup, use the "Quick Find" box to search for Permission Sets and click on it.
    Click the New button.
    Create a Label for the permission set (e.g., " SuccessPro JWT API Auth Permissions”). The API Name will populate automatically.
    Click Save.
Step 8: Assign the Connected App to the Permission Set
    On the new permission set's page, find and click on Assigned Connected Apps.
    Click the Edit button.
    Select the SuccessPro Connected App from the "Available Connected Apps" list and click the Add arrow to move it to the "Enabled Connected Apps" list.
    Click Save.
Step 9: Assign the API User to the Permission Set
    On the new permission set's page, find and click "Manage Assignments".
    Click "Add Assignment" and select the API User.
    Click "Next", then click "Assign".
    Click "Done".

Wrapping Up:
After performing these steps, notify your ActiFi contact that the configurations have been updated. Please provide them with the Consumer Key for the Connected App. ActiFi will manage the cutover and testing for the new authentication scheme from their servers and will reach out if any issues arise.
Thank you!