salesloft-security-basics

v2026.09.24

Harden Salesloft tenant isolation, OAuth and API-key storage, least-privilege scopes, CRM-data handling, and webhook verification. Use when reviewing an integration security boundary. Trigger with "Salesloft security", "secure Salesloft tokens", or "Salesloft webhook verification".

GitHub
Install command
npx skhub add jeremylongshore/salesloft-security-basics
Markdown
SKILL.md

Salesloft Integration Security Boundary

Overview

This skill reviews how credentials, tenant context, prospect data, mutations, and webhook deliveries move through an integration. It produces remediations tied to evidence and named owners.

Prerequisites

  • Architecture, data-flow, scope, and secret inventories
  • Named Salesloft teams, environments, and data owners
  • Current webhook subscription configuration
  • Incident and credential-rotation procedures

Tool Discipline

Use Read, Glob, and Grep to inspect auth, logging, storage, routing, and signature code. Use WebFetch only for official Salesloft security contracts. Use Write or Edit only after the remediation target is confirmed.

Current Contract

  • Every API credential is a Bearer secret and must remain server-side.
  • Authorization-code refresh rotates the refresh token; client credentials have no refresh token.
  • API keys act as the issuing customer user and are not the partner application path.
  • x-salesloft-signature is a hex SHA-1 HMAC of the exact request body using callback_token as the key.
  • Salesloft does not document a timestamp header in the general delivery-header contract, so do not invent timestamp replay verification.

Authentication

Bind each encrypted credential record to one Salesloft team, flow, scope set, environment, owner, and rotation state. Fail closed when tenant context is missing or mismatched.

Instructions

  1. Trace credential acquisition, storage, decryption, refresh, injection, revocation, and audit events.
  2. Verify least-privilege scopes against every used method and path.
  3. Enforce explicit tenant context across queues, caches, jobs, logs, and database keys.
  4. Redact Authorization, token, callback-token, email, phone, and CRM fields from diagnostics.
  5. Verify webhook HMAC over exact raw bytes with equal-length constant-time comparison.
  6. Validate the event type and callback token, then apply durable deduplication before side effects.
  7. Test rotation, tenant-confusion, invalid-signature, deletion, and incident paths.

Approval Boundaries

Do not broaden scopes, export customer data, create or revoke credentials, delete Salesloft records, or rotate production secrets without named owner approval and rollback planning.

Output

Return tenant and data-flow findings, scope delta, secret lifecycle, webhook-verification result, redaction gaps, prioritized fixes, owners, and verification evidence.

Error Handling

ConditionResponse
Tenant mismatchFail closed and investigate cross-team exposure.
Signature length differsReject before constant-time comparison.
Credential exposureRevoke or rotate, contain logs, and follow incident procedure.
Uncertain deleteStop; Salesloft documents person deletion as not normally reversible.

Examples

The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.

tenant-binding=pass; scopes=least-privilege; webhook-hmac=pass; pii-log-gaps=0

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/salesloft-security-basics

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8