R1D39 Secrets in Salesforce
My entire Trailhead journey started because I wanted to write a couple of custom integrations for work. I made a working POC hacking together various bits and pieces of information that I found online, but taking a step back to actually learn how Salesforce works has been really great.
I am ready to make a non-hacky solution to the problem that I initially set out to solve. In order to get this to work though, I need some way to manage secrets within Salesforce so that I can securely store my API authentication token for the third party service that I am integrating with.
Luckily, there is Trailhead module on Secure Secret Storage in Salesforce.
Salesforce offers a feature called Named Credentials which offers a very straightforward way to manage secrets. Specifically those involving authenticating against a third party API.
Rather than hard-coding the value into your code, you can leverage named credentials to store secrets, allowing you to refer to the named credential to access the secret value, as if it were any other variable in your code.Sadly, this did not seem to work for me because the API I was using expects a token in the URL rather than allowing for basic authentication.
There are a couple other strategies in place for storing secrets, but they seem like overkill for my specific project.
Thank you for reading! Share your thoughts with me on bluesky, mastodon, or via email.
Check out some more stuff to read down below.
Most popular posts this month
- SQLite DB Migrations with PRAGMA user_version
- Lev Lazinskiy
- Edge Detection with Inkscape
- Org Mode To Google Docs and Beyond
- Spring Security, Webjars, and MIME type error
Recent Favorite Blog Posts
This is a collection of the last 8 posts that I bookmarked.
- Deeper dive: Were Touch Bar’s problems software rather than hardware? from Unsung
- Joining Cursor from Fatih Arslan
- Pluralistic: Digital sewer socialism (08 Aug 2026) from Pluralistic: Daily links from Cory Doctorow
- Pluralistic: Enshittification and Reverse Centaurs go global (29 Jul 2026) from Pluralistic: Daily links from Cory Doctorow
- AI Mania Is Eviscerating Global Decision-Making from Ludicity
- The default person from https://popagandhi.com/
- No-One Escapes the Permanent Underclass from Fernando Borretti
- Is it ethical to use AI? from charity.wtf
Articles from blogs I follow around the net
“This way, the interface does not get in the way.”
Ilya Birman on his blog talks about interfaces that unnecessarily slow people down, in a series of two posts. In the first one, titled “Let me click,” Birman shows a few places that force the user to go through a roundabout series of clicks, instead of tak...
via Unsung August 24, 2026Anger, Anxiety and Agency
Sean Goedecke wrote a post arguing that you should never be angry at work — a post with which I strongly agree. Anger can be a useful signal, but being angry at work rarely improves the situation. More often, it makes life worse for the people around you,...
via Armin Ronacher's Thoughts and Writings August 24, 2026Advice to Young Developers
Someone recently asked me what advice I’d give to a young developer today. My answer had surprisingly little to do with code. Here’s what I’d focus on: Learn How to Build Products Even if LLMs write most of the code, there is still a need for problem solve...
via Matthias Endler August 24, 2026Generated by openring