> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Start Salesforce's authorization flow for a workspace.



## OpenAPI

````yaml /openapi-public.json get /connections/salesforce/start
openapi: 3.1.1
info:
  title: Klef API
  description: Klef's multi-tenant HRIS sync platform API.
  version: v1
servers:
  - url: https://{workspace}.klef.ai/api
    variables:
      workspace:
        default: acme
        description: Your workspace's subdomain.
security: []
tags:
  - name: Users
  - name: Connections
  - name: Adoption
  - name: Policy resources
  - name: Audit
  - name: Catalog
  - name: Sync
  - name: Search
  - name: SyncPlans
  - name: Agent
  - name: Auth
  - name: Workspaces
  - name: Billing
  - name: Invitations
  - name: FirstSignIns
  - name: Connection accounts
  - name: Policies
  - name: Secrets
  - name: Lookup tables
  - name: Scripts
  - name: Segments
  - name: ApiKeys
  - name: Members
  - name: Workers
  - name: Inbox
  - name: Notifications
paths:
  /connections/salesforce/start:
    get:
      tags:
        - Connections
      summary: Start Salesforce's authorization flow for a workspace.
      operationId: StartSalesforceAuthorization
      parameters:
        - name: workspace
          in: query
          required: true
          schema:
            type: string
        - name: returnUrl
          in: query
          schema:
            type: string
      responses:
        '302':
          description: Found
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '503':
          description: Service Unavailable
      security:
        - cookieAuth: []
        - apiKeyAuth: []
components:
  securitySchemes:
    cookieAuth:
      type: apiKey
      description: >-
        Cookie-based session. Obtain by completing the `/auth/login/{provider}`
        OAuth flow; the `/auth/callback` response sets the `klef.session` cookie
        that subsequent requests send automatically.
      name: klef.session
      in: cookie
    apiKeyAuth:
      type: http
      description: >-
        An API key from **Settings > API keys**, sent as `Authorization: Bearer
        klef_sk_…`. A key works only on its own workspace's subdomain, and only
        with the permissions its scopes grant.
      scheme: bearer
      bearerFormat: klef_sk_…

````