Skip to content
CPQ Compass
← Back

For your Salesforce admin

What this app needs access to, and what to allow

Send this page to whoever administers your Salesforce org. It lists exactly what is requested, why, and the three settings that most commonly block it.

What is being requested

Two OAuth scopes, and nothing else:

  • api — read CPQ configuration. Salesforce has no read-only variant of this scope; read-only is enforced on our side, where the Salesforce client issues GET and has no write path at all.
  • refresh_token — so a scan that outlives a short-lived access token can finish.

No full, no web, no offline user impersonation. The connecting user only ever sees data their own profile already permits. What we read, in detail

1. Approving the app

Since September 2025, Salesforce blocks uninstalled connected apps for most users.

The permission that allows it — Approve Uninstalled Connected Apps — is assigned to the System Administrator profile by default. So an admin connecting their own org usually needs to do nothing here.

A non-admin user will be blocked. If the person running the scan is not a System Administrator, they need that permission, or the app installed and their profile permitted.

If your org has API Access Control enabled, every connected app is blocked until allowlisted, and no user-level permission changes that. The app has to be installed and approved, or the user granted Use Any API Client. Symptom: the connection fails with “isn’t approved by an admin to access this app”.

2. IP restrictions

The scan runs from a server, not from the browser that authorized it.

Authorization happens in the user’s browser, but every subsequent API call comes from our server. If the user’s profile has Login IP Ranges set, that server address has to be permitted.

All requests originate from a single static address: 158.69.220.65. It does not rotate.

One caution worth knowing before you change anything: if you relax IP restrictions on the connected app and the org has Enforce login IP ranges on every request enabled, Salesforce documents that access can break in some cases. Allowlisting the address on the profile is the more predictable route.

Because this is a profile-level setting, it can look inconsistent: two admins in the same org, one connects and one cannot.

3. API access on the profile

The connecting user needs API Enabled.

Without API Enabled the sign-in can succeed and the first API call still fail. It is on most admin profiles already.

If your org requires its own login URL

Many orgs disable login.salesforce.comand require their own My Domain. The connect screen accepts a Salesforce URL directly, so there is nothing to configure — use the org’s own .my.salesforce.com address.

Nothing here asks you to lower your org’s security posture. If the answer to any of the above is no, the scan simply does not run — there is no degraded mode that reads more than it should.

Revoking

Setup → Connected Apps OAuth Usage → revoke, at any time, without telling us. Access ends immediately. The app name to look for is CPQ Migration Scanner.