In BlogPost, Ruby

Working with the Salesforce OAuth and Salesforce REST API

picture of cat representing salesforce oauth for rest api

Recently, I had to add some code to a Rails application to create a Contact via the Salesforce API when another action happened in a Rails controller. Essentially this meant I couldn’t use the traditional three-legged OAuth flow. I needed to provide credentials and get an access token to allow me to issue commands via the Salesforce REST API. The first thing on my plate to do for this tasker was to try and do it via the cURL command line tool.

How the authentication flow works with cURL:

This process is for “Session ID Authorization” as outlined in

Step 1 – setup a connected app (or use an existing one such as Jazz) to get the client_secret and client_id (called consumer_secret and consumer_key in Salesforce)

Step 2 – Issue a cURL request with the following format to get the access_token:

curl -H "application/x-www-form-urlencoded" -d "grant_type=password" -d "client_id=XXXXX" -d "client_secret=12345YYYY" -d "[email protected]" -d "password="

Note that password above is your salesforce password concatenated with your security token (obtained by clicking Reset Security Token in the Salesforce interface). Also, in production, you would use as the URL to fetch the access token from instead of

You will get back an access token in a response similar to below:

Step 3 – issue another cURL request with the access_token obtained from Step 2 to the salesforce REST API (example below creates a contact)

Example access_token


Example of creating a contact

When you make a call to the Salesforce API, you will use the instance url from the access token response in the above example.

curl "" -H "Authorization: Bearer BY123!xxx" -H "Content-Type: application/json; charset=UTF-8" -d '{"lastname": "TestExample", "email": "[email protected]"}'


  • Note in the above example there is an exclamation point in the access token. When issuing a cURL command in bash shell, there is a “history expansion” going on. If you try to escape the “!” with a “”, you will get an INVALID_SESSION_ID error.
  • 2 workarounds: Issue the cURL request through Postman chrome plugin/app OR turn off history expansion in your shell.

Token expiration

The token expires according to your Organization’s default settings in Salesforce.

Once you have the token, you can now issue commands to the Salesforce REST API.

Recent Posts
side projectvim logo