Skip to main content
In this section, we provide guides and references to use the Salesforce connector. Configure and schedule Salesforce metadata workflows from the OpenMetadata UI:

Requirements

These are the permissions you will require to fetch the metadata from Salesforce.
  • API Access: You must have the API Enabled permission in your Salesforce organization.
  • Object Permissions: You must have read access to the Salesforce objects that you want to ingest.

Metadata Ingestion

To ingest metadata from Salesforce, you need to create a service connection. The service connects Salesforce with OpenMetadata. Once you create a service, OpenMetadata automatically starts ingesting metadata.

Step 1: Add New Service

  1. Navigate to Settings > Services. Navigate to Settings and Services
  2. Click Add New Service. Add New Service

Step 2: Select a Service and Connector

From the service type dropdown, select Database Services, then click the Salesforce connector tile. Select Service

Step 3: Add Service Name and Description

  • Enter a unique, descriptive Service Name. OpenMetadata identifies services by their service name. Enter a name that distinguishes this deployment from other Salesforce services you are ingesting metadata from.
  • Optional: Enter a Description for the service.
Configure Service
Note: The service name cannot be changed after it is set.

Step 4: Configure Connection Options

Specify your source credentials and verify the connection.

Enter Connection Details

Enter the connection details for Salesforce. The right-hand panel in the UI displays inline help for each field. Configure Service Connection Authentication OpenMetadata supports two authentication methods for Salesforce:
  • OAuth 2.0 (Recommended): Authenticate using a Salesforce Connected App (External Client App) with a Consumer Key and Consumer Secret. See the Salesforce External Client Apps documentation to set one up.
    • Consumer Key: Salesforce Consumer Key (Client ID) for OAuth 2.0 authentication. Obtained from your Salesforce Connected App configuration. Provide this together with Consumer Secret to use OAuth 2.0.
    • Consumer Secret: Salesforce Consumer Secret (Client Secret) for OAuth 2.0 authentication. Obtained from your Salesforce Connected App configuration. Provide this together with Consumer Key to use OAuth 2.0.
    Which OAuth flow applies depends on your Salesforce Domain setting:
    • OAuth password flow (most common): Provide Consumer Key and Consumer Secret together with Username and Password. Works with login or test as the Salesforce Domain.
    • Client credentials flow (no username/password): Provide only Consumer Key and Consumer Secret. Requires your Salesforce My Domain as the domain value (for example, mycompany.my). Does not work with login or test.
  • Username / Password (Legacy)
    Important: Salesforce is deprecating direct username/password API access. Migrate to OAuth 2.0 using a Connected App (External Client App) to avoid future disruption. See Salesforce OAuth documentation.
    • Username: Username to connect to Salesforce. This user should have the access as defined in requirements.
    • Password: Password to connect to Salesforce.
    • Security Token: Salesforce Security Token is required for username/password authentication. See the Salesforce Security Token documentation to get your security token.
Common Fields
  • Organization ID: Salesforce Organization ID is the unique identifier for your Salesforce identity. You can check out this doc on how to get your Salesforce Organization ID.
    You need to provide the 15 digit organization id in this section, for example 00DIB000004nDEq, which you can find by following the steps mentioned in the doc above (Salesforce dashboard -> Setup -> Company Profile -> Company Information -> Salesforce.com Organization Id).
    If you want to access Salesforce metadata without a token (only by using organization id), you will need to set up your IP in trusted IP ranges. Go to Salesforce dashboard -> Setup -> Security -> Network Access -> Trusted IP Ranges to configure this. You can check here to configure your ip in trusted ip ranges.
  • Salesforce Object Names: List of Salesforce Object Names to ingest. If left blank, all objects will be ingested (subject to filter patterns).
  • Database Name: Optional name to give to the database in OpenMetadata. Defaults to default if left blank.
  • Salesforce API Version: The API version to use when connecting to Salesforce. The correct value depends on your authentication method:
    • OAuth 2.0 (password flow or client credentials): Use any current Salesforce-supported version, including 65.0 or higher.
    • Username / Password (Legacy): Use 64.0 or lower. Salesforce removed the SOAP login() endpoint in API version 65.0, which the legacy username/password flow relies on, so setting 65.0 or higher will cause login failures. Note that API versions 31.0 through 64.0 are also scheduled to be retired by Salesforce in mid-2027, so we recommend migrating to OAuth 2.0 before that date.
    Follow the steps mentioned here to find your org’s API version.
    The connector’s default API version is 42.0. For OAuth 2.0, we recommend setting a newer current version (for example, 59.0 or higher) for access to the latest Salesforce features. For the legacy Username/Password flow, keep it at 64.0 or lower to avoid login failures.
  • Salesforce Domain: Specify the Salesforce domain (subdomain only) to use for authentication. This field accepts only the domain prefix, not the full URL. Common values:
    • login (default) - For production instances (resolves to https://login.salesforce.com)
    • test - For sandbox instances (resolves to https://test.salesforce.com)
    For Salesforce My Domain: Enter your custom domain prefix, including all subdomain components such as .my or .sandbox.my, but without .salesforce.com. Examples:
    • If your My Domain URL is https://mycompany.my.salesforce.com, enter: mycompany.my
    • If your sandbox My Domain URL is https://mycompany--uat.sandbox.my.salesforce.com, enter: mycompany--uat.sandbox.my
    • If your URL is https://example-dot-com--uat.sandbox.my.salesforce.com, enter: example-dot-com--uat.sandbox.my
    Important: Do NOT enter the full URL or include .salesforce.com. Only enter the subdomain prefix as shown in the examples above.
SSL Configuration In order to integrate SSL in the Metadata Ingestion Config, the user will have to add the SSL config under sslConfig which is placed in the source.

Test Connection

Once the credentials have been added, click on Test Connection and Save the changes. Test Connection

Step 5: Configure Ingestion Options

In the What to Ingest step, use filter patterns to control which assets OpenMetadata ingests from your database service. Filter patterns use regular expressions applied to asset names.

How Filter Patterns Work

  • Include: Add one or more comma-separated regular expressions. OpenMetadata ingests only assets whose names match at least one expression. Leave blank to include all assets.
  • Exclude: Add one or more comma-separated regular expressions. OpenMetadata skips any asset whose name matches an expression. Leave blank to exclude nothing.
Rules match asset names using one of five expressions:
  • contains: matches any name containing the value. For example, sales matches my_sales_data and sales_2024.
  • starts with: matches names beginning with the value. For example, prod_ matches prod_db and prod_schema.
  • ends with: matches names ending with the value. For example, _raw matches events_raw and logs_raw.
  • is exactly: matches the exact name only. For example, analytics matches only analytics.
  • matches regex: matches names using a regular expression. For example, ^prod_.*_v\d+$ matches prod_events_v1.
When both Include and Exclude are set, Exclude takes priority.
Leave all filter patterns empty to ingest all databases, schemas, and tables available in the source.
Filter Options The Database, Schema, and Table sections each include the following filter options:
  • Database: Controls which databases OpenMetadata ingests from the source.
  • Schema: Controls which schemas within the ingested databases are included.
  • Table: Controls which tables and views within the ingested schemas are included.
Each section provides the following controls:
  • Scan Mode: You can choose between the following scan modes:
    • Scan all: Ingests every asset of that type the connector can access. This is the default.
    • Only specific: Enables include rules so only assets matching at least one rule are ingested.
  • Exclude system toggle: Use this toggle to automatically filter out system-reserved names defined by the connector, for example, Exclude system databases for the Databases section.
  • Always exclude: Add permanent exclusion rules (shown in red). Assets matching these rules are never ingested, regardless of include rules.
  • Preview: Shows a real-time summary of what will be in scope based on your current rules.
  • Include rules (available only in Only specific mode): Click + Add to define a rule. Added rules appear as chips; an asset is included if it matches any rule.

Step 6: Create & Deploy

Click Create & Deploy to deploy the agent and start the first metadata ingestion run. OpenMetadata saves the service configuration and immediately begins pulling metadata from the source. To monitor ingestion progress or view the service you just added, go to Settings > Services and select your service.

Configure Metadata Agent and Schedule Ingestion

The Metadata Agent extracts schemas, tables, columns, and other structural metadata from your source and keeps your OpenMetadata catalog in sync. It powers discovery, lineage, and governance across your data assets. When you click Create & Deploy, OpenMetadata automatically deploys a Metadata Agent for this service and triggers the first ingestion run. View its status and run history from the Agents tab on the service detail page. To configure the additional Metadata Agent and schedule ingestion, follow these steps:
  1. Navigate to Settings > Services and select the service type. Navigate to Settings and Services
  2. Click the service you have added.
  3. Select the Agents tab and click Add Agent > Metadata. Add Metadata Agent For some services, the dropdown is not available and clicking Add Agent takes you directly to the agent configuration page.
  4. On the Configure Ingestion page, do the following and click Next.
    • Name this Ingestion: Enter a unique recognizable name for this ingestion pipeline. Name this Ingestion
    • Agent Setup: Configure core parameters for metadata extraction. The following fields are available: Agent Setup
    • Filter Patterns: Apply include or exclude rules to scope which databases, schemas, tables, and stored procedures this agent ingests. For more information about various filter options, see Step 6: Configure Ingestion Options. Filter Patterns
    • Scope & Behaviour: Control how the agent handles metadata during ingestion. Toggle each option on or off based on your needs:
      Available toggles vary by connector. Stored procedure options only appear for connectors that support stored procedures.
      Scope & Behaviour
    • Advanced Config: Optional connector-specific settings such as Include Views and Extract JSON Schema. Advanced Config
  5. On the Schedule Interval page, set when the agent runs:
    • Schedule: Choose a preset interval (Hourly, Daily, Weekly, Monthly) or enter a custom cron expression.
    • On-Demand: No automatic schedule; trigger the agent manually when needed.
    Schedule Interval
  6. Click Add to deploy the agent.

Securing Salesforce Connection with SSL in OpenMetadata

To establish secure connections between OpenMetadata and Salesforce, navigate to the Advanced Config section. Here, you can provide the CA certificate used for SSL validation by specifying the caCertificate. Alternatively, if both client and server require mutual authentication, you’ll need to use all three parameters: ssl_key, ssl_cert, and ssl_ca. In this case, ssl_cert is used for the client’s SSL certificate, ssl_key for the private key associated with the SSL certificate, and ssl_ca for the CA certificate to validate the server’s certificate. SSL Configuration

Usage Workflow

Learn more about how to configure the Usage Workflow to ingest Query information from the UI.

Lineage Workflow

Learn more about how to configure the Lineage from the UI.

Profiler Workflow

Learn more about how to configure the Data Profiler from the UI.

Data Quality Workflow

Learn more about how to configure the Data Quality tests from the UI.

dbt Integration

Learn more about how to ingest dbt models’ definitions and their lineage.