integration-connectivity-generate
forcedotcom/sf-skills
Salesforce integration architecture: Named Credentials, External Services, REST/SOAP callouts, Platform Events, and CDC patterns.
What is integration-connectivity-generate?
Expert guidance for setting up Salesforce integration plumbing including authentication, outbound callouts, and event-driven patterns. Use this skill when configuring Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, or Change Data Capture—but delegate OAuth app setup, Apex-only logic, data import/export, and CDC channel metadata to related skills.
- Design and generate Named Credentials and External Credentials metadata for secure runtime authentication
- Create External Service registrations from OpenAPI specifications
- Generate REST and SOAP callout patterns with timeout, retry, and error handling
- Design Platform Events and Change Data Capture event-driven architectures
- Choose between synchronous and asynchronous integration patterns based on requirements
- Validate operational safety including logging, retries, and async strategies
How to install integration-connectivity-generate
npx skills add https://github.com/forcedotcom/sf-skills --skill integration-connectivity-generate- Salesforce CLI (sf) version 2.0.0 or later
- jq version 1.6.0 or later for JSON processing
- npm version 9.0.0 or later
- Python 3.10.0 or later for validation scripts
- Salesforce org with API version 61.0 or later
How to use integration-connectivity-generate
- 1.Gather integration requirements: style (callout, event, External Service, CDC), auth method, sync vs async needs, endpoint details, and rate limits
- 2.Choose the integration pattern from the recommended workflow table (Named Credential, External Service, Platform Events, or CDC)
- 3.Select the appropriate auth model, preferring External Credentials for new development
- 4.Generate metadata files from provided templates in assets/ directories (named-credentials, external-credentials, external-services, callouts, platform-events, cdc)
- 5.Validate operational safety: confirm timeout handling, retry strategy, async patterns for triggers, and logging/observability
- 6.Hand off to platform-metadata-deploy for deployment or platform-apex-generate for advanced service code
Use cases
- Setting up authenticated outbound API calls to third-party systems using Named Credentials
- Registering spec-driven API clients via External Services from OpenAPI definitions
- Designing event-driven integrations using Platform Events for decoupled publishing and subscription
- Implementing Change Data Capture to consume change streams from Salesforce objects
- Creating async callout patterns to avoid synchronous trigger callouts
- Salesforce integration architects designing system-to-system communication
- Developers building outbound REST/SOAP integrations
- Teams implementing event-driven or CDC-based data synchronization
- Administrators configuring secure credential management for external APIs
integration-connectivity-generate FAQ
Use this skill for integration architecture and runtime plumbing (Named Credentials, callouts, events). Use integration-connectivity-connected-app-configure only for OAuth app setup (consumer key, certificate, app configuration).
No. This is an anti-pattern. Use async patterns (Queueable, scheduled actions, or event-driven) for trigger-originated work to avoid blocking and governor limit issues.
Named Credentials support OAuth, JWT, Certificate, and Custom auth. External Credentials support OAuth and JWT. Always use runtime-managed auth—never hardcode credentials in code.
Use Platform Events for explicit, application-driven event publishing. Use CDC for automatic change-stream consumption when you need to react to object changes without modifying trigger logic.
Validate with the provided scripts, then delegate deployment to platform-metadata-deploy skill and deeper Apex implementation to platform-apex-generate skill if needed.
Full instructions (SKILL.md)
Source of truth, from forcedotcom/sf-skills.
name: integration-connectivity-generate description: "Salesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use integration-connectivity-connected-app-configure), Apex-only logic (use platform-apex-generate), data import/export (use platform-data-manage), or CDC channel-membership metadata such as PlatformEventChannel, PlatformEventChannelMember, or EnrichedField (use integration-eventing-cdc-configure)." metadata: version: "1.1" domains: ["Integration"] minApiVersion: "61.0" relatedSkills: - "agentforce-generate" - "automation-flow-generate" - "integration-connectivity-connected-app-configure" - "integration-eventing-cdc-configure" - "platform-apex-generate" - "platform-data-manage" - "platform-metadata-deploy" cliTools: - tool: ["jq"] semver: ">=1.6.0" - tool: ["npm"] semver: ">=9.0.0" - tool: ["python3"] semver: ">=3.10.0" - tool: ["sf"] semver: ">=2.0.0"
integration-connectivity-generate: Salesforce Integration Patterns Expert
Use this skill when the user needs integration architecture and runtime plumbing: Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, CDC, and event-driven integration design.
When This Skill Owns the Task
Use integration-connectivity-generate when the work involves:
.namedCredential-meta.xmlor External Credential metadata- outbound REST/SOAP callouts
- External Service registration from OpenAPI specs
- Platform Events, CDC, and event-driven architecture
- choosing sync vs async integration patterns
Delegate elsewhere when the user is:
- configuring the OAuth app itself → integration-connectivity-connected-app-configure
- writing Apex-only business logic → the
platform-apex-generateskill - deploying metadata → the
platform-metadata-deployskill - importing/exporting data → the
platform-data-manageskill
Required Context to Gather First
Ask for or infer:
- integration style: outbound callout, inbound event, External Service, CDC, platform event
- auth method
- sync vs async requirement
- system endpoint / spec details
- rate limits, retry expectations, and failure tolerance
- whether this is net-new design or repair of an existing integration
Recommended Workflow
1. Choose the integration pattern
| Need | Default pattern |
|---|---|
| authenticated outbound API call | Named Credential / External Credential + Apex or Flow |
| spec-driven API client | External Service |
| trigger-originated callout | async callout pattern |
| decoupled event publishing | Platform Events |
| change-stream consumption | CDC |
2. Choose the auth model
Prefer secure runtime-managed auth:
- Named Credentials / External Credentials
- OAuth or JWT via the right credential model
- no hardcoded secrets in code
3. Generate from the right templates
Use the provided assets under:
assets/named-credentials/assets/external-credentials/assets/external-services/assets/callouts/assets/platform-events/assets/cdc/assets/soap/
4. Validate operational safety
Check:
- timeout and retry handling
- async strategy for trigger-originated work
- logging / observability
- event retention and subscriber implications
5. Hand off deployment or implementation details
Use:
- the
platform-metadata-deployskill for deployment - the
platform-apex-generateskill for deeper service / retry code - the
automation-flow-generateskill for declarative HTTP callout orchestration
High-Signal Rules
- never hardcode credentials
- do not do synchronous callouts from triggers
- define timeout behavior explicitly
- plan retries for transient failures
- use middleware / event-driven patterns when outbound volume is high
- prefer External Credentials architecture for new development when supported
Common anti-patterns:
- sync trigger callouts
- no retry or dead-letter strategy
- no request/response logging
- mixing auth setup responsibilities with runtime integration design
Output Format
When finishing, report in this order:
- Integration pattern chosen
- Auth model chosen
- Files created or updated
- Operational safeguards
- Deployment / testing next step
Suggested shape:
Integration: <summary>
Pattern: <named credential / external service / event / cdc / callout>
Files: <paths>
Safety: <timeouts, retries, async, logging>
Next step: <deploy, register, test, or implement>
Cross-Skill Integration
| Need | Delegate to | Reason |
|---|---|---|
| OAuth app setup | integration-connectivity-connected-app-configure | consumer key / cert / app config |
| advanced callout service code | platform-apex-generate skill | Apex implementation |
| declarative HTTP callout / Flow wrapper | automation-flow-generate skill | Flow orchestration |
| deploy integration metadata | platform-metadata-deploy skill | validation and rollout |
| use integration from Agentforce | agentforce-generate skill | agent action composition |
Reference Map
Start here
- references/named-credentials-guide.md
- references/external-services-guide.md
- references/callout-patterns.md
- references/rest-callout-patterns.md
- references/security-best-practices.md
Event-driven / platform patterns
- references/event-patterns.md
- references/platform-events-guide.md
- references/cdc-guide.md
- references/event-driven-architecture-guide.md
- references/messaging-api-v2.md
CLI / automation / scoring
- references/cli-reference.md
- references/named-credentials-automation.md
- references/scoring-rubric.md
- scripts/README.md — automation scripts overview (configure-named-credential.sh, set-api-credential.sh)
Asset templates
assets/named-credentials/— Named Credential XML templates (OAuth, JWT, Certificate, Custom auth)assets/external-credentials/— External Credential XML templates (OAuth, JWT)assets/external-services/— External Service registration template and operations guideassets/callouts/— REST sync, Queueable, retry handler, and HTTP response handler Apex templatesassets/platform-events/— Platform Event definition, publisher, and subscriber templatesassets/cdc/— CDC handler and subscriber trigger templatesassets/soap/— SOAP callout service template and wsdl2apex guideassets/endpoint-security/— Remote Site Setting and CSP Trusted Site XML templates
Automation hooks
scripts/suggest_credential_setup.py— auto-suggests credential configuration steps when integration files are detectedscripts/validate_integration.py— validates integration patterns before agent responses
Output Expectations
When this skill completes an integration task, it produces:
- Credential metadata — one or more files in
assets/named-credentials/orassets/external-credentials/filled with org-specific values - Callout Apex class — a
.clsfile using the Named Credential pattern, with async/sync pattern chosen based on context - Event/CDC artifacts — Platform Event
.object-meta.xml, subscriber trigger, or CDC config (when event-driven pattern is chosen) - Endpoint security metadata — Remote Site Setting and/or CSP Trusted Site XML files
- Scoring report — 120-point score across 6 categories (Security, Error Handling, Bulkification, Architecture, Best Practices, Documentation)
- Next step — a deployment or testing instruction for the generated artifacts
Score Guide
| Score | Meaning |
|---|---|
| 108+ | strong production-ready integration design |
| 90–107 | good design with some hardening left |
| 72–89 | workable but needs architectural review |
| < 72 | unsafe / incomplete for deployment |
Pre-Delivery Checklist
- Never hardcode credentials — all secrets stored in Named Credentials or External Credentials
Related skills
More from forcedotcom/sf-skills and the wider catalog.

integration-eventing-cdc-configure
Enable and configure Salesforce Change Data Capture on objects with custom channels, filters, and enrichment fields.

integration-eventing-subscription-configure
Create, read, update, and delete ManagedEventSubscription metadata for Salesforce platform event subscriptions.

investigating-agentforce-architecture
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins. Renders a human-readable architecture document and Mermaid invocation graph from design-time metadata (not runtime audit rows). TRIGGER when user asks to describe, diagram, inventory, audit, document, or diff (e.g. v3 vs v5) the architecture / action tree / topic structure / tool inventory of a specific agent by agent API name in a specific org. DO NOT TRIGGER for runtime session traces, conversation transcripts, generation timings, or gateway audit chains — this skill reads design-time metadata only (use investigating-agentforce-d360 for session traces).

investigating-agentforce-d360
Data Cloud 360° view of a single Agentforce session. TRIGGER when user asks to trace, inspect, summarize, or describe a specific Agentforce session by session id (Agent Session UUID `019d…` or MessagingSession id `0Mw…`). Also triggers on session discovery — find/list/search sessions by time, agent, channel, outcome, or conversation text — when the user has no session id yet. DO NOT TRIGGER for design-time architecture questions (use investigating-agentforce-architecture instead) or for runtime perf/latency/SLO questions that require platform telemetry beyond Data Cloud.

managing-managed-event-subscription
Create, read, update, and delete ManagedEventSubscription metadata in Salesforce. Use this skill for any work involving managed event subscriptions, platform event subscriptions, event channel subscribers, or .managedEventSubscription-meta.xml files. TRIGGER when: user asks to subscribe to a platform event, create a managed subscription, set up event replay, configure an event channel subscriber, update replay preset, activate or deactivate a subscription, delete a subscription, or manage ManagedEventSubscription metadata. SKIP when: user needs to create the platform event channel itself (use generating-platform-event skill) or needs Flow-based event subscriptions (use generating-flow skill).

mobile-apps-create
Route Salesforce mobile app projects to the right SDK: Mobile SDK for data-driven apps, Agentforce SDK for agent-first experiences.