BYOK requires an app to connect to the Cloud Service Provider Account created in the CSP Vault.

To create a connected app 

  1. In Salesforce, start the App Manager.
  2. Click New Connected App.

  3. In the Create a Connected App window, select Create a Connected App and click Continue.

  4. In the New Connected App window, complete the following: 

  5. At the bottom of the window, click Save.

  6. On the New Connected App page, click Continue. 

    It may take up to 10 minutes to finish creating the connected app.

  7. In the sidebar, click Manage Connected Apps.

  8. On the Connected Apps page, locate the connected app that you created and click Edit.

  9. On the Connected App Details page, click Edit Policies.

  10. In the Run As section under Client Credentials Flow, select a user with the permissions to manage keys and secrets and click Save.

  11. In the sidebar, click App Manager.

  12. Locate the app that you just created and select View.

  13. In the API (Enable OAuth Settings) section, click Manage Consumer Details.

  14. Wait for Salesforce to email you a verification code. 

  15. Enter the verification code and click Verify.

  16. Copy the Consumer Key and the Consumer Secret. 

     Use these values to connect to the CSP Vault.

Basic Information 

Configure the following settings.

Field

Description

Connected App Name

Enter the name to use for the connected app.

API Name

Enter the connected app API name.

Contact Email

Enter your email address.

API (Enable OAuth Settings) 

Configure the following settings and click OK in the confirmation box.

Field

Value

Enable OAuth Settings

Check this box

Enable for Device Flow

Check this box

Callback URL

Accept the default URL

OAuth Scopes

Select Manage User Data via APIs (api)

Require Proof Key for Code Exchange (PKCE)

Check this box

Require Secret for Web Server Flow

Check this box

Require Secret for Refresh Token Flow

Check this box

Enable Client Credentials Flow

Check this box.