.png)

Salesforce Experience Cloud Integration Guide
Salesforce Experience Cloud integrates with enterprise systems through Salesforce REST, GraphQL, SOAP, Bulk, file, analytics, and configured event APIs.
Salesforce Experience Cloud integration options at a glance
Salesforce Experience Cloud data is accessed through Salesforce platform APIs rather than a conventional site database. REST APIs support SOQL queries, CRUD operations, composite requests, and resource-specific capabilities, while GraphQL is available for supported schemas and use cases. SOAP remains relevant for established enterprise integrations, and Bulk API 2.0 supports high-volume asynchronous extraction and ingestion. Salesforce Files use ContentVersion, ContentDocument, and ContentDocumentLink APIs. Selected changes can be delivered through Change Data Capture, Platform Events, Streaming API, Pub/Sub API, Outbound Messages, or Apex callouts. Martini can authenticate through an OAuth-connected app, orchestrate these calls, transform payloads, and expose controlled APIs for downstream systems.
Common Salesforce Experience Cloud integration patterns
Common Salesforce Experience Cloud data objects used in integrations
Authentication and security considerations
OAuth and connected apps
Salesforce API access should use a connected app and an OAuth flow appropriate to the integration. JWT bearer is suitable for many server-to-server scenarios, while authorization-code flows support delegated access. Other documented flows should be evaluated against the security requirements.
Permissions and site access
API access depends on the integration user's object permissions, field-level security, record sharing, profile and permission-set configuration, connected-app policies, and API version. Salesforce API access does not automatically reproduce the permissions of an Experience Cloud site user.
Secrets and data protection
- Store client secrets, certificates, refresh tokens, and environment-specific values in protected Martini configuration.
- Restrict connected-app scopes and integration-user permissions to the required objects and fields.
- Review external-user licensing, site membership, guest-user restrictions, Knowledge visibility, and file-sharing rules.
- Protect personally identifiable information in User, Contact, Account, and Case payloads.
Operational considerations for Salesforce Experience Cloud integrations
Limits and pagination
Salesforce applies org-level and product-specific API limits. Use composite or Bulk API operations where appropriate, avoid unnecessary polling, follow nextRecordsUrl for REST queries, and monitor asynchronous bulk job states.
Incremental processing
Use Change Data Capture or other configured events where suitable. Scheduled workflows should persist SystemModstamp-based or equivalent high-water marks and use stable query boundaries.
Idempotency and retries
Use Salesforce IDs, external IDs, deterministic correlation keys, and duplicate detection before creating records. Retry transient failures with bounded backoff, but do not replay non-idempotent creates without duplicate protection.
Schema and access changes
Salesforce administrators can change fields, picklists, permissions, sharing, API versions, and Experience Cloud audience settings. Validate mappings and describe metadata during testing and review integrations after relevant Salesforce deployments.
Events and files
Event delivery may be delayed, duplicated, or out of order, so persist event or replay information and reconcile through APIs. Handle ContentVersion, ContentDocument, and ContentDocumentLink separately from ordinary object fields, including binary content and visibility rules.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration instead of isolated scripts
Martini provides a workflow layer for authentication, API calls, event intake, transformations, business rules, target writes, and exception handling. This keeps Salesforce integration behavior visible and maintainable as Experience Cloud processes evolve.
Reusable integration assets
Teams can expose controlled Martini APIs, reuse mappings and workflow services, and support REST, GraphQL, SOAP, Bulk, files, and callbacks without building a separate point-to-point script for each target system.
Operational control
- Apply consistent pagination, checkpointing, idempotency, and retry behavior.
- Separate technical failures from Salesforce validation and authorization exceptions.
- Monitor workflow execution and preserve correlation information for troubleshooting.
- Keep Salesforce credentials and environment-specific configuration outside integration logic.