salesforce app implements Salesforce APIs over isolated app data. An app version supplies a predefined catalog, configuration records, and record rules. Creating an environment does not connect to a customer’s Salesforce organization or import its metadata.
Protocols and operations
Paths below use{version} for a supported Salesforce API version. This differs from the State Machines app version, which identifies the replica release.
REST paths after the discovery row are relative to
/services/data/v{version}. The resource directory lists a subset of the registered routes. Its omission of composite or Tooling does not mean those routes are absent.
The app version’s apis declares protocol compatibility. Retrieve versions with sm.apps.versions('salesforce') and match the environment’s selected app version. Each API entry lists its apiVersions and limitations. Native REST discovery lists served API versions.
REST, SOAP Partner, and the identity URL serve API versions 31.0 to 67.0. Bulk API 2.0 serves 47.0 to 67.0. A REST request below 31.0 returns HTTP 410 (GONE), and any other unserved version returns 404 (NOT_FOUND). Version 67.0 is the seed version. The replica’s catalog and behavior were recorded from a Salesforce organization at that version, and older versions are projections of it.
Authentication and actors
env.connect('salesforce') selects the default administrator actor. If you assigned another name to the app at creation, pass that name instead. Pass an actorId from the selected app version to use another available actor.
Object access, field access, record sharing, and API permissions depend on the actor. An administrator’s successful request does not establish that another actor can make it.
SOAP requires the actor token in the envelope’s SessionHeader/sessionId. See credentials and actors for the headers every app request needs.
SOAP Partner operations
The SOAP adapter supports these operations:- Sessions and identity:
login,logout,getUserInfo, andgetServerTimestamp. - Discovery:
describeGlobal,describeSObject, anddescribeSObjects. - Records:
create,update,upsert,delete,undelete, andretrieve. - Queries:
query,queryAll, andqueryMore. - Replication:
getDeletedandgetUpdated.
merge and convertLead return INVALID_OPERATION. The Enterprise SOAP API is unsupported.
SOAP login() returns INVALID_OPERATION at API version 65.0 and later. From 31.0 to 64.0 it requires settings.soapApiLoginEnabled: true, which is off by default, and a user with the Use Any API Auth permission. Other SOAP operations accept the actor token from connect() in SessionHeader/sessionId without calling login().
OAuth operations
The token endpoint implementspassword, refresh_token, client_credentials, and JWT bearer grants. Grant success depends on the connected app and credentials supplied to the replica. A client-credentials grant requires a configured run-as user. JWT bearer requires a valid assertion signed for the configured connected app. These protocol implementations do not imply that every environment supplies credentials for every grant.
The revoke endpoint accepts access or refresh tokens. The userinfo and identity endpoints return information for the authenticated user. The replica does not provide a browser authorization-code flow.
App settings
The public Salesforce app settings accept the following structure. These keys belong to the Salesforce app’s settings, not the top-level environment settings.
The validator rejects unknown keys and invalid values. Names and usernames must be nonempty strings of at most 80 characters. Startup reports rejected settings as
invalid_settings.
These settings customize predefined records and the SOAP login policy. They do not define custom objects, custom fields, packages, formulas, Flow definitions, or Apex code.
Request limits and error formats
The replica countsDailyApiRequests over a rolling 24-hour window and reports it in /limits and in the Sforce-Limit-Info response header. It does not refuse requests over the limit. Every other limit reports Remaining equal to Max. These values do not represent a customer’s Salesforce subscription.
State Machines accepts request bodies up to 20 MiB and returns responses up to 4 MiB.
REST errors use arrays with message, errorCode, and sometimes fields. Bulk errors use arrays with errorCode and message. SOAP returns a soapenv:Fault. OAuth uses error and error_description. See request troubleshooting for the separate State Machines error formats.
For task instructions, see records and schema, SOQL queries, and Bulk jobs. Read known differences before choosing compatibility assertions.