What problem does it solve?
Teams and engineers struggle to design, harden, and migrate Salesforce OAuth applications safely across orgs while respecting metadata conventions, secret handling, and modern security controls. This Skill centralizes templates, scoring, and migration guidance so integrations are deployable, auditable, and secure.
Core Features & Use Cases
- Templates & Metadata: Ready-to-use Connected App and External Client App (ECA) XML templates for common flows including JWT, PKCE, and full OAuth configurations.
- Security Scoring & Checklist: A 120-point validator and actionable checklist to harden scopes, callbacks, token policies, and certificate/rotation strategies.
- Migration & Deployment Guidance: Step-by-step migration plans, file naming conventions, deploy/retrieve commands, and post-deploy verification for migrating Connected Apps → ECAs.
- Use Case Examples: Generate CI/CD JWT apps, PKCE-enabled mobile ECAs, or review existing .connectedApp-meta.xml and .eca-meta.xml files for security remediation.
Quick Start
Use the sf-connected-apps skill to generate or review Connected App or External Client App metadata, pick an OAuth flow (e.g., PKCE or JWT), and produce deployable XML files with a security score and migration checklist.