How to Connect Thrico to Salesforce CRM
Step-by-step administrator guide to integrate Salesforce Developer, Enterprise, and Unlimited editions with Thrico via OAuth 2.0 PKCE.
The Thrico-Salesforce integration connects your CRM data with your Thrico community platform, enabling bi-directional contact synchronization, automatic member provisioning, and rule-based community assignments.
🌟 Overview
Connecting Salesforce to Thrico bridges customer relationship records directly with member community spaces and engagement activities.
Key Capabilities:
- 🔄 Real-Time Sync: Automatically provision and update Thrico community profiles when contacts, leads, or accounts change in Salesforce.
- 🏷️ Custom Field Mapping: Map standard (
Email,Phone,Title) and custom Salesforce fields (Membership_Tier__c,Points__c,Industry) to Thrico member attributes. - 🛡️ Enterprise Security: Uses OAuth 2.0 with RFC 7636 PKCE (Proof Key for Code Exchange) and AES-256 encrypted token storage at rest.
- ⚡ Zero-Code Setup: Connect in under 2 minutes through the Thrico Admin Dashboard.
📋 Prerequisites
Before starting the setup, ensure you have:
- A Salesforce Org (Production, Developer Edition, or Sandbox) with System Administrator rights or the
Customize Applicationpermission. - An active Thrico Admin Dashboard account with Admin privileges.
🚀 Step-by-Step Connection Guide
Step 1: Create an External Client App in Salesforce
- Log in to your Salesforce instance (login.salesforce.com or your custom domain).
- Click the Gear Icon (⚙️) in the top right header → select Setup.
- In the left-hand Quick Find box, type
App Managerand select it under the Apps menu. - In the top-right corner, click:
New External Client App(in modern Salesforce Lightning)
— OR —New Connected App(in Salesforce Classic / Standard Setup)
Salesforce External Client Apps are the modern successor to Connected Apps and provide enhanced OAuth security scoping. Both types are fully supported by Thrico.
Step 2: Configure App Details & OAuth Settings
-
In the Basic Information section, provide:
- App Name:
Thrico Community Integration - API Name:
Thrico_Community_Integration - Contact Email:
your-admin-email@yourdomain.com
- App Name:
-
Check the box: ☑️ Enable OAuth Settings (or Enable OAuth).
-
In the Callback URL field, enter your Thrico endpoint:
-
Under Selected OAuth Scopes, select and move the following 4 scopes to Selected:
Manage user data via APIs (api)Perform requests at any time (refresh_token, offline_access)Access unique user identifiers (openid)Full access (full)
-
Under Security / Flow Policies:
- ☑️ Check Require Secret for Web Server Flow
- ☑️ Check Require Proof Key for Code Exchange (PKCE)
-
Click Save, then click Continue.
New External Client Apps and Connected Apps in Salesforce can take 2 to 10 minutes to propagate across Salesforce global OAuth servers before they can accept authorization requests.
Step 3: Retrieve Consumer Key & Secret
- Under the OAuth Policies or Manage Consumer Details section of your newly created app, click
Manage Consumer Details(or View Consumer Details). - Salesforce may prompt you for a 2FA verification code sent to your admin email.
- Copy the two generated security keys:
- 🔑 Consumer Key (Client ID)
- 🔒 Consumer Secret (Client Secret)
Never share or commit your Consumer Secret into public repositories. Thrico encrypts and securely manages tokens using AES-256 GCM.
Step 4: Authorize from the Thrico Dashboard
- Open your Thrico Dashboard → navigate to:
- Locate the Salesforce CRM card and click
Connect Salesforce. - Choose your Salesforce environment:
- Production / Developer Edition (
login.salesforce.com) - Sandbox (
test.salesforce.com)
- Production / Developer Edition (
- You will be redirected to the secure Salesforce OAuth authorization screen.
- Review the requested permissions and click Allow.
- You will be automatically redirected back to Thrico with the status badge updated to CONNECTED.
⚙️ Post-Connection Setup
Once your Salesforce integration is active, configure your data pipeline:
1. Schema Discovery & Custom Field Mapping
Navigate to the Field Mapping tab:
- Thrico automatically queries your Salesforce metadata API to discover all standard and custom fields (
Account.Industry,LeadSource,Membership_Tier__c,Points__c). - Map any Salesforce field directly to Thrico member profiles or custom member attributes.
- Configure value transformations (e.g. uppercase, lowercase, enum dictionary mapping, date conversions).
2. Initial Data Import
Navigate to the Sync & History tab:
- Click
⚡ Sync Nowto initiate an initial bulk import of your Salesforce contacts and accounts. - View real-time sync progress, logs, processed records, and reconciliation metrics.
3. Automated Community Rules
Navigate to the Community Rules tab to configure dynamic membership workflows:
- Rule Example: If
Account_Tier == "VIP", automatically assign the member to the VIP Private Space. - Rule Example: If
Contact.Status == "Inactive", restrict access to private discussion channels.
🔒 Security & Data Governance
| Feature | Standard / Specification |
|---|---|
| Authentication Protocol | OAuth 2.0 with RFC 7636 SHA-256 PKCE & Web Server Flow |
| Token Encryption | AES-256 GCM Encryption at Rest with KMS Key Rotation |
| Data in Transit | TLS 1.3 End-to-End Encryption |
| API Limit Protection | Automated rate limiting with batching & incremental delta sync |
| Compliance | SOC 2 Type II and GDPR Compliant Data Handling |