Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To call an external REST API from Apex, configure a modern Salesforce Named Credential for the endpoint and authentication, grant the required users access, then send an HTTP request to that credential’s endpoint from Apex. Validate the response and plan for errors such as HTTP 503. Test the credential in a sandbox or test org—not production.

What an Apex callout does—and when to use one

An Apex callout sends an HTTP request from Salesforce to an external service. It is useful when your Salesforce code needs to read or update data in another system. For Salesforce records and metadata, first check whether Lightning Data Service (LDS) supports the entity and operation; it covers many common needs. Use Apex when you need Salesforce APIs or entities outside LDS’s supported subset. See Salesforce’s guidance on calling APIs from Apex.

For sObject extraction, migrations, synchronization, analytics, and record queries, Salesforce advises using the standard REST or SOAP APIs rather than the Connect REST API. The REST API Quick Start introduces Salesforce’s REST API; an Apex callout to an external API is a separate direction of communication.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Named Credentials for authenticated callouts

Salesforce recommends the extensible Named Credentials model introduced in Winter ’23. Legacy Named Credentials are deprecated and are scheduled to be discontinued in a future release. A Named Credential identifies the endpoint and transport; an External Credential defines the authentication configuration. Its principals map access to user permissions, while user external credentials store encrypted tokens. Review Salesforce’s Named Credentials guide for current setup details.

This separation lets you keep endpoint configuration and authentication out of the request logic, while controlling which users can use the credential. Grant access to the External Credential principal only to users who need it. Salesforce also cautions that authenticated callouts should be reviewed carefully: sessions created by Lightning are not generally enabled for API access.

Plan the integration before writing Apex

Identify the external API’s base endpoint and resource path, HTTP method, expected request and response formats, authentication scheme, and error behavior. Confirm what the service expects and what your Apex code must do when it returns an error or an unexpected payload. These decisions inform both the credential configuration and request handling.

Configure the credential and make the request

  1. Set up an External Credential. Choose the authentication method the external API requires and configure its principal.
  2. Set up a Named Credential. Point it to the API endpoint and associate the appropriate External Credential.
  3. Grant principal access. Give only the relevant users permission to use the configured principal.
  4. Send the callout from Apex. Create an HTTP request for the intended method and resource path, use the Named Credential as the endpoint, and send the request. Consult the current Apex Developer Guide for exact HttpRequest, HttpResponse, and Http.send syntax; those details are not established by the Salesforce sources linked here.
  5. Validate the response. Check the HTTP status and confirm that the response body has the shape your code expects before using it. Decide how to report failures or retry when appropriate to the external API.

Handle limits and service failures

Do not assume a universal Salesforce API quota from a generic callout example. Limits depend on the API and org and can change. Salesforce says most Connect REST API requests share the platform’s API limits, while some Chatter resources have a per-user, per-application, per-hour limit. Its Connect REST API limits documentation also notes that rate limiting can produce HTTP 503 responses and advises handling them gracefully.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build error handling around the service’s documented responses: distinguish unsuccessful status codes from successful responses, avoid treating an error body as valid data, and choose retry behavior that will not worsen a rate-limit or availability problem. The appropriate policy depends on the API’s own guarantees.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test credentials and callouts safely

Verify the target-org credentials in a sandbox or test org. Salesforce specifically warns against testing credentials in production; follow its target-org credential testing guidance.

Callout tests should use mocks rather than rely on a live external service. Salesforce’s 2018 Platform Developer II exam guide refers to Test.setMock() and HttpCalloutMock, but because that guide is dated, check the current Apex testing documentation for syntax and supported APIs before implementing a test.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.