SourceLace Docs
Open the app

Salesforce, Data 360 and Marketing Cloud

How to connect Salesforce (Sales and Service Cloud), Salesforce Data 360 and Salesforce Marketing Cloud Engagement: what your Salesforce admin installs, the options, what people can read and change, and what error messages mean.

Salesforce

Each person signs in with their own Salesforce login (OAuth with PKCE). Salesforce then applies their profile, permission sets, field-level security and sharing rules to everything SourceLace reads or changes.

What your Salesforce admin does (once per org)

SourceLace signs people in through its own Salesforce External Client App, delivered as a managed package. Salesforce only lets people use an app that is installed in their org, so your admin installs it once. Ask support@sourcelace.com for the install link. Trying it in a sandbox first is a good habit.

  1. Install. Open the install link while logged in to the org. For a sandbox, change login.salesforce.com in the link to test.salesforce.com. Choose Install for Admins Only (access is given in step 3), tick that you understand the package is not yet authorized for distribution through AppExchange, and click Install.
  2. Open the app's policies. Setup → External Client App Manager → SourceLace → Policies → Edit.
  3. Decide who may use it. Under OAuth Policies, set Permitted Users to Admin approved users are pre-authorized, save, and give access through a permission set: Setup → Permission Sets → New (for example "SourceLace users"), then under Assigned Connected Apps / External Client Apps add SourceLace, and assign the permission set to the people who will use it. Or leave All users may self-authorize, and each person approves the app the first time they connect.
  4. Optional: set IP relaxation, session timeout and refresh token policy to your security team's standard. SourceLace works with the defaults.

Exact labels can differ a little between Salesforce releases; Salesforce's help page "External Client App OAuth policies" has the current names.

The app asks Salesforce for the scopes Manage user data via APIs (api) and Perform requests at any time (refresh_token, offline_access), and for Data 360, also cdp_query_api and cdp_profile_api. It requires PKCE. Its callback URL is SourceLace's redirect URL (https://sourcelace.onrender.com/connect/callback), which travels with the package.

Add the source (SourceLace admin)

On Manage sources → Add a source, choose Salesforce, or ask in chat: "Add a SourceLace source salesforce:prod, kind salesforce, label Corvanta Salesforce, login URL https://corvanta.my.salesforce.com".

Option Type Default Example What it is
login_url Address https://login.salesforce.com https://corvanta.my.salesforce.com Where people sign in. The org's My Domain (https://<name>.my.salesforce.com) works for everyone and is the safest choice. https://login.salesforce.com works for most production orgs, and https://test.salesforce.com (or the sandbox's My Domain, https://<name>--<sandbox>.sandbox.my.salesforce.com) for sandboxes.

Only Salesforce's own addresses are accepted. A Lightning address copied from the browser (https://<name>.lightning.force.com) is turned into the matching My Domain automatically. After someone signs in, SourceLace sends every request to the org address Salesforce gives back, so the login address only matters for signing in.

What people can do

  • Find objects and fields: search_schema and describe_object list standard and custom objects and fields, picklist values and relationships, limited to what the person can see.
  • Query: one SOQL SELECT, such as SELECT Name, Amount FROM Opportunity WHERE IsClosed = false ORDER BY Amount DESC LIMIT 20. Anything that is not a single read-only SOQL query is refused before Salesforce is called.
  • Read a record: get_record with an 18- or 15-character record id, plus up to 3 related lists.
  • Change records (create, update, delete), only on objects your SourceLace admin made writable (such as Account, Opportunity, Case). The preview checks the person's object and field permissions and, for existing records, their sharing access. An update is refused if the record changed in Salesforce after the preview. The result includes the previous values, so a change can be undone; deleted records go to Salesforce's Recycle Bin.

When something goes wrong

What you see What to do
OAUTH_APP_BLOCKED, or "app is not installed" The package is not installed in that org, or the person lacks access. See steps 1 and 3 above.
OAUTH_APPROVAL_ERROR_GENERIC, or "user is not admin approved" Assign the person the permission set from step 3.
redirect_uri_mismatch Contact SourceLace support: the redirect URL travels with the package.
"Salesforce sign-in did not work at ...: it answered with a redirect (or a web page) instead of a token. Check the login URL ..." The login_url is mistyped or outdated. Use the org's current My Domain, or https://login.salesforce.com.
"The Salesforce login URL for ... must be login.salesforce.com, test.salesforce.com, or the org's My Domain" Only Salesforce addresses are accepted in login_url.
"The Salesforce login URL for ... must be a plain https:// address." Remove any path, port or ?... from login_url.
"Salesforce sign-in failed: ..." Salesforce's own reason follows. Often the person's profile cannot use the app (see step 3), or their account is locked.
"Salesforce answered with a web page instead of data ... The org may be under maintenance, or its address changed" Wait for maintenance to end, or connect again on Data Sources.
"Salesforce moved this org to a new address." or "Your Salesforce session has expired." SourceLace refreshes the sign-in itself; if it then asks, connect again.
"Salesforce: MALFORMED_QUERY: ..." or "Salesforce: INVALID_FIELD: ..." Salesforce's own message about the query. The AI usually fixes the query itself.
"Your Salesforce user cannot update Opportunity records." (or create, delete) The person's Salesforce profile does not allow it. Change their permissions in Salesforce if they should.
"... cannot be set on update (read-only or not permitted for you)." That field is read-only for the person in Salesforce.
"This ... record changed in Salesforce after the preview. Propose the change again." Someone else changed the record. Ask for a new preview.

Data 360

Data 360 (formerly Data Cloud) lives inside your Salesforce org, so it uses the same app and the same sign-in as Salesforce: SourceLace signs the person in to Salesforce, then exchanges that sign-in for a Data 360 token for the same person, so Data 360 still decides what each person can see. Read-only.

What your Salesforce admin does: install the SourceLace package as above, and give each person a Data 360 permission set, such as Data Cloud User or Data Cloud Admin (names vary by release). Without one, signing in to Salesforce works but Salesforce refuses the Data 360 token.

Add the source: kind Data 360 (data360), with the same login_url option as Salesforce.

What people can do:

  • search_schema and describe_object list data model objects (names ending in __dlm), data lake objects (__dll) and calculated insights (__cio), with their fields.
  • query takes one SQL SELECT (or WITH ... SELECT), such as SELECT ssot__FirstName__c FROM ssot__Individual__dlm LIMIT 10. Anything that could change data and anything with more than one statement is refused before it reaches Data 360.
  • get_record looks a row up by the object's primary key, and can add rows from related objects.
What you see What to do
"Data 360 sign-in failed... Check that Data 360 is on in this org, that you have a Data 360 permission set, and that SourceLace's app has the cdp_query_api and cdp_profile_api scopes." Give the person a Data 360 permission set. If it still fails, contact support. If they connected before Data 360 was set up, connect again.
"Data 360 has no object called ... that you can read. Try search_schema." The object name is wrong, or the person cannot see it.
"Data 360 is taking too long to run this query. Try a narrower query." Add filters or a LIMIT.

Marketing Cloud

Marketing Cloud Engagement is a separate account from your Salesforce org, with its own logins, so it uses its own app. Each person signs in with their own Marketing Cloud login, and Marketing Cloud applies their roles and business unit access. Everything is read-only.

Setup is done together with SourceLace support, because Marketing Cloud's app (an installed package) is registered in your Marketing Cloud account and its Client Id and Client Secret are added to SourceLace's server. Your Marketing Cloud admin:

  1. Goes to Setup → Platform Tools → Apps → Installed Packages and clicks New. Name: "SourceLace".
  2. Clicks Add Component, chooses API Integration, then Web App.
  3. Sets the redirect URI to https://sourcelace.onrender.com/connect/callback.
  4. Gives it read access only: Data Extensions: Read, Journeys: Read, Saved Content: Read and Email: Read (plus SMS: Read if you use SMS). Leaves every Write, Send and Delete box unticked.
  5. Saves, and sends the Client Id and Client Secret to SourceLace support over a secure channel we agree with you. Notes the Authentication Base URI, such as https://mc1a2b3c4d5e6f.auth.marketingcloudapis.com/.

Add the source: kind Marketing Cloud (sfmc).

Option Type Default Example What it is
subdomain Text (required) mc1a2b3c4d5e6f The part of the Authentication Base URI before .auth.marketingcloudapis.com.
account_id Number (none) 123456789 Optional: the business unit's MID, to sign in to that business unit.

What people can do:

  • search_schema finds data extensions, each named by its external key. describe_object lists its fields and marks the primary key.
  • query (language sfmc_rest) takes a GET path, optionally with options after ?. Only these are allowed: data extension rows (/data/v1/customobjectdata/key/<key>/rowset, such as .../key/Customers/rowset?$pageSize=50&$filter=Tier eq 'Gold'), the data extensions themselves (/data/v1/customobjects), journeys (/interaction/v1/interactions), Content Builder assets (/asset/v1/content/assets), and email and SMS send definitions (/messaging/v1/email/definitions, /messaging/v1/sms/definitions; read only, nothing is sent).
  • get_record looks one data extension row up by its primary key value.
  • Data extension keys with spaces, or punctuation other than -, _ and ., are not supported yet.
What you see What to do
"The sfmc connector is switched off on this server..." The installed package has not been added to SourceLace yet. Contact support.
"Set the Marketing Cloud subdomain for ... (the part before .auth.marketingcloudapis.com)." Fill in the subdomain option.
"The Marketing Cloud account_id for ... must be a number (the MID)." Use the business unit's numeric MID.
"That Marketing Cloud endpoint is not on the read allowlist." Only the read paths listed above are allowed.
"Marketing Cloud has no data extension with key ... that you can read." Check the external key with search_schema.
"Marketing Cloud sign-in failed: ..." Marketing Cloud's own reason follows. Check the person's Marketing Cloud user has access to the business unit.