Referencing the Canvas SDK
Getting Context in Your Canvas App
Alternatives to Cookies for User Tracking
Debugging in a Canvas App
Using the <select> Tag in a Canvas App
Lightning Component Code Examples
Canvas Limits
Previous Versions
Canvas is a set of tools that enable you to integrate your apps within Salesforce. This framework includes an SDK that you can use to authenticate your app and retrieve data from Salesforce.
To prepare your Canvas apps for the new web browser restrictions on third-party cookies, see How Third-Party Cookie Restrictions Impact Salesforce Canvas Apps in Salesforce Help.
Important
The Canvas SDK and code examples are available on GitHub at https://github.com/forcedotcom/salesforcecanvasframeworksdk.
The Canvas SDK is versioned and matches the API version in each release. The current version is 68.0. To check the version of the SDK that you have, call the version method.
When you create a Canvas app, you can use the signed request authentication method or the OAuth 2.0 authentication method.
Canvas apps are loaded on a Salesforce page in an iFrame. The Canvas app has its own domain and can’t make XML HTTP request (XHR) calls back to the *.salesforce.com domain. You can develop and deploy your own proxies as part of the SDK, however, Canvas provides a client-side proxy written in JavaScript. This proxy enables client-side XHR calls back to Salesforce.
Alternatives to Cookies for User Tracking
When creating websites and applications, the HTML <iframe> element lets you display third-party content within the current page window. As modern browsers have increased privacy for end users, the iframe structure is becoming more scrutinized and restricted. Third-party applications exposed as Canvas apps are surfaced in the Salesforce user interface via an iframe. To avoid problems loading your Canvas apps in Salesforce, design applications that don’t rely on cookies, session storage, or local storage to track users.
See Also