Use Connected Apps with OAuth Policies

Nintex DocGen for Salesforce supports Salesforce authorization and authentication through Connected Apps. With Connected Apps enabled, administrators can configure security policies that give them greater control over who can access the system and how users authenticate their credentials during a package run. Additionally, features such as dynamic image replacement with Rich Text fields and document generation from Salesforce Reports require Connected Apps to function properly. Nintex DocGen for Salesforce is automatically added to Connected Apps in Salesforce when a package is installed. You do not need to add it manually.

Authorize a Salesforce account

In order to run DocGen Packages, users must authorize their Salesforce account. Users can authorize their accounts by using one of the following:

  • The authorization link sent to them via email from Admins. Users only need to do this once.

  • The Authorize and Run button in the Lightning component when running a DocGen Package. As with the first method, users only need to complete this authorization once.

Enable Connected Apps

Important: Nintex DocGen for Salesforce package versions 21.2 and later have Connected Apps enabled by default.

Administrators can use the Connected Apps toggle in Nintex Admin to enable or disable Connected Apps. To use this option:

  1. Click the Nintex Admin tab.

  2. The Nintex Admin Home left navigation displays.

  3. Under Configuration, click Settings.

  4. In the Connected Apps and OAuth box, switch the toggle to Active to authorize and authenticate Connected Apps.

  5. Click Save to confirm the change.

  6. Connected Apps has now been enabled for Nintex DocGen and you can integrate your connected apps with Nintex DocGen. Continue to use the same steps to authorize any other organizations, such as test or demo environments.

Transition to the Nintex DocGen for Salesforce Modern connected app

To support Salesforce's Mandatory Security Updates for Connected Apps, Nintex DocGen for Salesforce version 21.12 introduces a new connected app, Nintex DocGen for Salesforce Modern to support enhanced OAuth security control.

Upgrade your Nintex DocGen for Salesforce package

To access the new connected app, install Nintex DocGen for Salesforce version 21.12 or later from the Salesforce AppExchange. For more information, see Install or upgrade from within Salesforce Lightning.

Important: The existing Nintex DocGen for Salesforce connected app remains available to enable transition to the new connected app.

Since the upgrade is security-focused, your DocGen Packages, templates, relationships, delivery options, and previously generated documents will remain unchanged. Your current setup will continue to function as normal with the upgrade.

Add your configuration to the Nintex DocGen for Salesforce Modern connected app

After the upgrade, copy your configuration settings from the existing Nintex DocGen for Salesforce connected app to the newly installed connected app, Nintex DocGen for Salesforce Modern.

  1. In Salesforce Setup, search for App Manager.

  2. Locate Nintex DocGen for Salesforce and Nintex DocGen for Salesforce Modern.

  3. Click Manage to view your configuration settings.

  4. Ensure that you copy all your configuration settings from Nintex DocGen for Salesforce to Nintex DocGen for Salesforce Modern.
    These settings include any OAuth policies, permitted profiles and permission sets, and any other custom configuration your environment requires.

Reauthorize your account

After you upgrade and add your configuration, users must reauthorize their Salesforce account for Nintex DocGen for Salesforce Modern. The OAuth policy configured for the connected app determines which users must manually reauthorize their Salesforce account. For more information on policies, see Configure Policies for Permitted Users.

  • If the connected app is configured with the Admin approved users are pre-authorized OAuth policy, only integration user must reauthorize. Other users’ reauthorization will be automatically handled by Salesforce via Profiles and/or Permission Sets.

  • If the connected app is configured with the All users may self-authorize OAuth policy, all users, including the integration user, must reauthorize their Salesforce account after the upgrade. For more information on how to reauthorize, see Authorize a Salesforce account.

Important: The reauthorization link is single-use and cannot be shared among multiple users.

Configure Policies for Permitted Users

By enabling Connected Apps, administrators have the ability to use pre-configured OAuth policies in Salesforce for greater control over who can access and use Nintex DocGen for Salesforce. Configuring policies allows you to control access for a permitted user. For more information, see Manage OAuth Access Policies for a Connected App.

There are two OAuth policies configured for Nintex DocGen:

All users may self-authorize

By using this option you are allowing permitted Nintex DocGen users with the ability to self-authorize by logging into their Salesforce account.

If this option is selected:

  • When a permitted user runs a package they will click the Run or Authorize & Run button. This is going to trigger the document generation process and the user receives a pop-up asking them to authorize . This authorization process is done by the user logging into their Salesforce account.

  • Users need to click the Allow button in the authorization pop-up to authorize their account. Once they are authorized the user can run the document package as normal.

  • Administrators can log in or subscribe as the user and run a DocGen Package as that user.

Caution: If you have a user configured to run an automated process using Flow or other automation, the user will need to be authorized or the auto-run process will not complete.

Admin approved users are pre-authorized

By using this option administrators can determine which Profiles are authorized to use Nintex DocGen.

If this option is selected:

  • Users are pre-authorized and are not prompted to log in when running a package.

  • Auto-runs are not going to be interrupted as there is no need for users of automated user processes to authorize.

  • Allows users to be added in to Profile and administrators can choose selected users in the Profile to test run a package as that user.

Note: By default, Nintex DocGen for Salesforce uses the All users may self-authorize profile. Please refer to Use Connected Apps with OAuth PoliciesConfigure Policies for Permitted Users section for more information.

To configure a policy for permitted Nintex DocGen for Salesforce users:

  1. From Setup, type "Manage Connected Apps" in the Quick Find box and select Manage Connected Apps.
  2. Click Nintex DocGen for Salesforce Modern. The Nintex DocGen for Salesforce Modern page appears.
  3. Click Edit Policies.
  4. Under OAuth Policies, locate the Permitted Users field.
  5. Select All users may self-authorize or Admin approved users are pre-authorized from the Permitted Users drop-down list.
  6. Click Save.

You have configured policies for your Nintex DocGen users.

Important: If the Permitted Users OAuth policy for Nintex DocGen for SalesforceModern is set to All users may self-authorize, enabling Connected Apps and OAuth will prompt all users to reauthorize when running a DocGen Package. Switching the setting to Admin approved users are pre-authorized will avoid this. If you are unable to change the setting, inform your users that they will need to manually reauthorize during document generation. For more information, see User Authorization Options via Salesforce Connected Apps