Protect an App Builder Workflow Integration

Applications / App Builder securityApp builders, workflow administrators, and platform administrators1 min read
What you’ll learnHow to use a connected page safely and what to do after an integration credential changes.

The credential used by an App Builder workflow connection is managed by the platform administrator. It is not configured from Applications, and native workflow forms do not use it.

Safety rules

  • Never place an integration credential in documentation, screenshots, tickets, logs, or page instructions.
  • Use connected App Builder pages only in the audience approved by your organization.
  • Use a native Private form for sensitive member-only intake, or a reviewed Public form when external access is intended.
  • Do not treat the Require Authentication option on a generated page connection as a substitute for workspace and page access controls.
  • Review the page after every deployment because pending App Builder changes can be published with the connection.

After a credential change

  1. The platform administrator identifies every App Builder page that uses a workflow or task connection.
  2. A builder opens each affected Start or Task step and saves the page connection again.
  3. Refresh the page in App Builder.
  4. Test the form or task with non-production data.
  5. Confirm that the workflow starts or the task action completes successfully.

If a connected page reports that the integration is unavailable or forbidden, do not paste credentials into the page. Ask the platform administrator to verify the server-managed configuration, then redeploy the affected connection.

Still stuck? See Get Help with Support or reach your workspace administrator.