Members can connect once Athena Intelligence has registered a Salesforce
connected app for your workspace. It can be Athena’s own app, or one your
Salesforce administrator creates in your org (step 1).
Step 1 — Prepare your org (Salesforce admin)
Depending on your org’s security settings:- Allow the app. If your org only allows connected apps it has installed, install the app from Setup → Connected Apps OAuth Usage, or give members the Approve Uninstalled Connected Apps permission.
- Choose who may connect. Under the app’s policies, All users may self-authorize lets any member with API access connect. Admin approved users are pre-authorized limits it to the profiles and permission sets you assign.
- Relax IP restrictions. If your profiles restrict login IP ranges, set the app’s IP relaxation to Relax IP restrictions.
- API access. Every member needs the API Enabled permission, on an edition that includes API access.
Optional — your own connected app
Create your own app when your org requires one, or when members can sign in only through your My Domain.- In Setup, create a connected app (or an external client app) and enable OAuth.
-
Set the Callback URL:
For private or VPC deployments, replace
api.athenaintel.comwith your environment’s Athena API host. Salesforce requires an exact match. - Select the scopes Manage user data via APIs (api), Perform requests at any time (refresh_token, offline_access) and Access the identity URL service (id, profile, email, address, phone).
- Keep Require secret for Web Server Flow on and Require Proof Key for Code Exchange (PKCE) off.
- Save, then copy the Consumer Key and Consumer Secret.
-
Send them to Athena Intelligence through a secure channel, with where your
members sign in:
login.salesforce.com(production),test.salesforce.com(sandboxes) or your My Domain, for exampleacme.my.salesforce.com.
Step 2 — Athena registers the app for your workspace
Athena Intelligence adds asalesforce_direct integration for your workspace.
It holds the Consumer Key, the encrypted Consumer Secret and the login host.
Secrets are encrypted at rest and never returned to the browser. Production
and sandboxes sign in at different hosts, so each gets its own integration.
Once one is saved, the Salesforce card on the Integrations page is
available to every member. Until then, the card says the integration isn’t set
up for the workspace yet.
Step 3 — Connect your account (each member)
- Navigate to Integrations and click Connect Salesforce on the Salesforce card, under CRM.
- Salesforce’s sign-in page opens in a popup. Sign in to the org you want to connect, then click Allow. Athena stores your encrypted tokens and confirms the connection with your Salesforce username.
- If your workspace has more than one integration registered (for example production and sandboxes), pick one before connecting. To add another org later, click Connect another Salesforce org.
What Athena can do
Once connected, the Salesforce toolkit gives agents these tools.
A few behaviors to know:
- Plain-language requests work. Ask “show my open opportunities closing this quarter”. Athena builds the SOQL query for you.
- Several orgs. With more than one org connected, name the org you mean.
- Setup objects are never written. Athena never writes users, profiles, permission sets, roles, sharing rows or Apex, whatever your permissions allow. There is no delete tool.
- Reads need no approval. Read tools run without a prompt in chat and in scheduled agent runs that act as you. Write tools are available only in chat, where you can approve them. An automation’s own identity holds no Salesforce connection, so automation steps cannot call Salesforce.
Use Salesforce from a computer
On a computer with your Salesforce connection attached under Connected Catalogs:SALESFORCE_INSTANCE_URLholds your org’s address.SALESFORCE_API_URLholds its REST API base,https://<your org>/services/data/v62.0.athena-catalog-token salesforce_directprints a short-lived access token for your connection.
salesforce_direct. The computer acts as you, so anyone you share
it with can use your Salesforce access from it: attach your connection only to
a computer you don’t share.
Token lifecycle & troubleshooting
- Everything is per-user. Results always reflect your Salesforce access, and every change is attributed to you.
- “Reconnect Salesforce.” The refresh token was revoked or expired (the app’s refresh token policy, a password reset, or an admin revoking the app). Reconnecting from the Integrations page fixes it.
- “redirect_uri_mismatch” in the popup. The app’s Callback URL doesn’t exactly match the one in step 1.
- “Salesforce API access is off for your user or org.” Your user needs the API Enabled permission.
- “Refused this as you.” Your profile, permission sets or sharing do not allow the request. Ask your Salesforce administrator; Athena cannot widen your access.
- API limits. When your org’s API allowance is used up, Athena says so instead of retrying.

