Managing Salesforce users in Spekit? This guide covers Salesforce MFA and SSO considerations, OAuth authorization, IP restriction setup, user licensing, and how to invite and onboard Salesforce users into Spekit.
📌 Quick-Jump Topics
- Salesforce MFA and SSO with Spekit: What to know about multi-factor authentication and single sign-on
- Salesforce OAuth Authorization for the Spekit App: How authentication works for admins and end-users
- How to Relax IP Restrictions for the Spekit OAuth in Salesforce: Resolving IP-blocked login issues
- Do Users Need a Salesforce License to Use Spekit: Who can access Spekit
- How to Invite a Salesforce User to Join Spekit: Syncing and inviting users from Salesforce
- How to Accept a Spekit Invite as a Salesforce User: Steps for new users to log in and install the extension
Salesforce Multi-Factor Authentication (MFA) and Single Sign-On (SSO) with Spekit
How does Salesforce MFA affect Spekit users?
- As of February 1, 2022, Salesforce requires all customers to enable multi-factor authentication (MFA) to access Salesforce.
- Users currently logged into Spekit with Salesforce will not be affected until they log out - at which point they will be required to complete MFA for Salesforce.
- If a user manually logs out, they will need to complete MFA for Salesforce again on their next login.
- Enabling SSO provides a one-click login experience with Spekit, removing the need for extra MFA codes from Salesforce each time.
- We encourage your organization to adopt Single Sign-On (SSO) to avoid additional login friction if your users log in with Salesforce to access Spekit.
If you have questions, please contact your Customer Success Manager to get the SSO process started with Spekit. Spekit supports Okta, OneLogin, PingOne, and Azure.
Salesforce OAuth Authorization for the Spekit App
How does OAuth authentication work between Salesforce and Spekit?
When setting up Spekit, users with a System Administrator profile in Spekit can authenticate with Salesforce using OAuth. End-users can sign in using Salesforce OAuth or sign in directly with their Spekit username and password.
For more technical details, refer to the Salesforce OAuth documentation.
How to Relax IP Restrictions for the Spekit OAuth in Salesforce
Why do I need to relax IP restrictions, and how do I do it?
Users in your organization logging in to Spekit with their Salesforce credentials may encounter an IP Blocked error. Relaxing IP restrictions for the Spekit OAuth app in Salesforce resolves this issue. A Salesforce Administrator must complete the following steps:
- Log in to your Salesforce org.
- Click Setup.
- In the Quick Find search bar, search for OAuth.
- Click Connected Apps OAuth Usage.
- Locate Spekit OAuth in the Connected Apps OAuth Usage list and click Manage App Policies.
- Locate the IP Restriction field - it will show Enforce IP restrictions. Click Edit Policies.
- Click the IP Restriction dropdown and select Relax IP restrictions.
- Scroll down and click Save.
- Confirm the IP Restriction field now shows Relax IP restrictions.
Do Users Need a Salesforce License to Use Spekit?
Is a Salesforce license required to access Spekit?
❌ No. While Spekit uses your Salesforce metadata as a baseline, the goal is to create a source of truth and reference for anyone in your organization - regardless of whether they have a Salesforce license.
Any Spekit user can access content in Spekit via the Web App or Chrome Extension without a Salesforce license.
How to Invite a Salesforce User to Join Spekit
How do I sync and invite Salesforce users to Spekit?
As an Account Admin, you must first sync your Salesforce instance before available Salesforce users will appear for invitation.
Step 1: Sync your Salesforce instance:
- From the Spekit Web App, go to Settings.
- Click Connect in the left navigation bar.
- Click the Sync now button in the Salesforce section. The sync process will begin.
- When the sync completes, you will see a blue notification in the bottom-left corner of the page and receive a confirmation email.
Step 2: Invite users:
- From the Spekit Web App, go to Settings and click Teams & Users in the left navigation bar.
- Click Invite Synced Salesforce Users.
- Select the users you want to invite and click the blue Invite button.
- Select a Team and a team-specific role for the users.
- Click the blue Add # user button.
A notification will appear in the bottom-left corner of your screen confirming User successfully invited.
How to Accept a Spekit Invite as a Salesforce User
What steps does a new Salesforce user take to accept their Spekit invite?
The invited Salesforce user will receive an Accept Invite email. Follow these steps to complete the onboarding:
- Open the invite email and click the blue Accept Invite button.
- You will be taken to a screen prompting you to log in with Salesforce. Click the blue Login with Salesforce button.
- You will be redirected to the Salesforce login screen. Enter your Salesforce username and password.
- You will be prompted to allow Spekit access to your Salesforce account. Click the blue Allow button to proceed.
- You will now be logged into the Spekit dashboard. Click Install from the Chrome Store to install the Spekit Chrome Extension.
- Click the blue Add to Chrome button to complete the Chrome Extension installation.