Get ready to create identity experiences that are convenient for your customers and partners and consistent with your brand. With new Headless Identity APIs for Login and Forgot Password, you can control the user experience in a third-party app while relying on Salesforce for authentication. Your users log in, access their data, and manage their passwords without leaving your app. Behind the scenes, your Salesforce implementation uses authentication APIs called via an Experience Cloud site to handle authenticating users, authorizing data access, and resetting passwords.
Where: This change applies to LWR, Aura, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Unlimited, and Developer editions.
How: Set up a headless login process with the Authorization Code and Credentials Flow, which is built on top of the OAuth 2.0 Authorization Code grant type. To complete your implementation, make it easy for users to reset their passwords with the Headless Forgot Password Flow.