Tython

Category

AI

AI security topics across the Salesforce ecosystem, from Agentforce to frontier model risk.

security · integrations · ai · apex · salesforce

Your Salesforce Org Needs a Bouncer: How OAuth Token Exchange Checks IDs at the Door

Secure your Salesforce Org by implementing the OAuth 2.0 Token Exchange flow, a programmatic 'bouncer' that validates IDs at the door for external integrations. This zero-trust approach utilizes an external Identity Provider (IdP) for authentication and a custom Apex handler for granular, scoped authorization in Salesforce. Token Exchange is essential for securing modern Agentic AI workflows that chain Salesforce into complex, multi-system processes.

Scott Covert ·

salesforce · ai · security

Project Glasswing and Claude Mythos: What Frontier AI Vulnerability Discovery Means for Salesforce

Anthropic’s Project Glasswing reveals that frontier AI can now autonomously find and exploit vulnerabilities in general-purpose code, including Salesforce Apex. Since Salesforce isn't part of the initial defensive coalition, the burden of securing custom code and managed packages falls entirely on individual customers. This shift marks the end of 'security through obscurity' for Salesforce orgs, requiring urgent audits and a move toward strict least-privilege architecture.

Scott Covert ·

← Back to all posts