Authentication

When you create a Canvas app, you can use the signed request authentication method or the OAuth 2.0 authentication method.

If your Canvas app URL contains a URL fragment identifier (#), then the hash mark (#) and all characters that follow are stripped from the URL during the authentication flow. To prevent unexpected behavior, avoid using hash marks (#) in a Canvas app URL.

Important

  • Signed request—The default method of authentication for Canvas apps. The signed request containing the consumer key, access token, and other contextual information is provided to the Canvas app in one of these ways.

    • The administrator allows access to the Canvas app for the user.
    • The user approves the Canvas app in the OAuth flow.
  • OAuth 2.0—Canvas apps can use the OAuth 2.0 protocol to authorize and acquire access tokens. For more information about OAuth and the Lightning Platform, see Authorize Apps with OAuth.

  • Signed Request Authentication

    Signed request is the default authorization method for Canvas apps. The signed request authorization flow varies depending on whether the administrator gives users access to the Canvas app or if users can self-authorize. You can verify signed request information with a client secret, then use signed requests to customize the app and make subsequent calls to Salesforce.

  • OAuth 2.0 Authorization

    Canvas supports the OAuth 2.0 web server flow and the OAuth 2.0 user-agent flow.

  • SAML Single Sign-On for Canvas Apps

    Whether you use signed request or OAuth authorization, you can use SAML-based single sign-on (SSO) to provide your users with a seamless authentication flow. You can leverage Salesforce as an identity provider or as a service provider. SAML SSO enables you to give your users automatic authentication into your canvas app via SAML and authentication into Salesforce via the signed request.

See Also