> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usestatemachines.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Salesforce API reference

> Supported protocols, authentication, app settings, and compatibility boundaries for the Salesforce replica.

The `salesforce` app implements Salesforce APIs over isolated app data. An app version supplies a predefined catalog, configuration records, and record rules. Creating an environment does not connect to a customer's Salesforce organization or import its metadata.

## Protocols and operations

Paths below use `{version}` for a supported Salesforce API version. This differs from the State Machines app version, which identifies the replica release.

| API | Paths and operations |
| - | - |
| REST discovery | `GET /services/data`, `GET /services/data/v{version}`, global describe at `/sobjects`, and object describe at `/sobjects/{object}/describe`. |
| REST records | Create, retrieve, update, and delete records by ID. Retrieve and upsert by external ID. Conditional reads and writes. |
| REST query | `/query`, `/queryAll`, and query locator pages. `DELETE /query/{locator}` returns HTTP `405` (`METHOD_NOT_ALLOWED`) and leaves the locator usable. |
| REST composite | `/composite`, `/composite/batch`, `/composite/graph`, `/composite/tree/{object}`, and sObject Collections. |
| REST limits and replication | `/limits`, `/limits/recordCount`, and each object's `/updated` and `/deleted` resources. |
| Bulk API 2.0 | Ingest and query jobs under `/services/data/v{version}/jobs`, CSV uploads, job state, and result retrieval. |
| SOAP Partner | `/services/Soap/u/{version}`, optionally followed by an organization ID. Supported operations are listed below. |
| OAuth | Token, revoke, and userinfo endpoints under `/services/oauth2`, plus `/id/{organization}/{user}`. |
| Tooling | Create, read, and delete `WorkflowOutboundMessage`. General Tooling API support is absent. |

REST paths after the discovery row are relative to `/services/data/v{version}`. The resource directory lists a subset of the registered routes. Its omission of composite or Tooling does not mean those routes are absent.

The app version's `apis` declares protocol compatibility. Retrieve versions with `sm.apps.versions('salesforce')` and match the environment's selected app version. Each API entry lists its `apiVersions` and `limitations`. Native REST discovery lists served API versions.

REST, SOAP Partner, and the identity URL serve API versions 31.0 to 67.0. Bulk API 2.0 serves 47.0 to 67.0. A REST request below 31.0 returns HTTP `410` (`GONE`), and any other unserved version returns `404` (`NOT_FOUND`). Version 67.0 is the seed version. The replica's catalog and behavior were recorded from a Salesforce organization at that version, and older versions are projections of it.

## Authentication and actors

`env.connect('salesforce')` selects the default administrator actor. If you assigned another name to the app at creation, pass that name instead. Pass an `actorId` from the selected app version to use another available actor.

Object access, field access, record sharing, and API permissions depend on the actor. An administrator's successful request does not establish that another actor can make it.

SOAP requires the actor token in the envelope's `SessionHeader/sessionId`. See [credentials and actors](/environments/credentials) for the headers every app request needs.

## SOAP Partner operations

The SOAP adapter supports these operations:

* Sessions and identity: `login`, `logout`, `getUserInfo`, and `getServerTimestamp`.
* Discovery: `describeGlobal`, `describeSObject`, and `describeSObjects`.
* Records: `create`, `update`, `upsert`, `delete`, `undelete`, and `retrieve`.
* Queries: `query`, `queryAll`, and `queryMore`.
* Replication: `getDeleted` and `getUpdated`.

`merge` and `convertLead` return `INVALID_OPERATION`. The Enterprise SOAP API is unsupported.

SOAP `login()` returns `INVALID_OPERATION` at API version 65.0 and later. From 31.0 to 64.0 it requires `settings.soapApiLoginEnabled: true`, which is off by default, and a user with the Use Any API Auth permission. Other SOAP operations accept the actor token from `connect()` in `SessionHeader/sessionId` without calling `login()`.

## OAuth operations

The token endpoint implements `password`, `refresh_token`, `client_credentials`, and JWT bearer grants. Grant success depends on the connected app and credentials supplied to the replica. A client-credentials grant requires a configured run-as user. JWT bearer requires a valid assertion signed for the configured connected app. These protocol implementations do not imply that every environment supplies credentials for every grant.

The revoke endpoint accepts access or refresh tokens. The userinfo and identity endpoints return information for the authenticated user. The replica does not provide a browser authorization-code flow.

## App settings

The public Salesforce app settings accept the following structure. These keys belong to the Salesforce app's settings, not the top-level environment settings.

| Key | Accepted configuration |
| - | - |
| `preset` | `development`, also used when omitted. |
| `configure.organization` | `target: { $ref: 'defaults.organization' }` and `values: { Name: string }`. |
| `configure.administrator` | `target: { $ref: 'defaults.administrator' }` and `values: { Username: string }`. |
| `settings.soapApiLoginEnabled` | A boolean. |

The validator rejects unknown keys and invalid values. Names and usernames must be nonempty strings of at most 80 characters. Startup reports rejected settings as `invalid_settings`.

These settings customize predefined records and the SOAP login policy. They do not define custom objects, custom fields, packages, formulas, Flow definitions, or Apex code.

## Request limits and error formats

The replica counts `DailyApiRequests` over a rolling 24-hour window and reports it in `/limits` and in the `Sforce-Limit-Info` response header. It does not refuse requests over the limit. Every other limit reports `Remaining` equal to `Max`. These values do not represent a customer's Salesforce subscription.

State Machines accepts request bodies up to 20 MiB and returns responses up to 4 MiB.

REST errors use arrays with `message`, `errorCode`, and sometimes `fields`. Bulk errors use arrays with `errorCode` and `message`. SOAP returns a `soapenv:Fault`. OAuth uses `error` and `error_description`. See [request troubleshooting](/troubleshooting/requests) for the separate State Machines error formats.

For task instructions, see [records and schema](/apps/salesforce-records), [SOQL queries](/apps/salesforce-query), and [Bulk jobs](/apps/salesforce-bulk). Read [known differences](/apps/known-differences) before choosing compatibility assertions.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.