Configure a Credential Payload
Bearer Token Credential setup creates a supporting Credential Payload for the token callout and credential update. Open that generated Payload to configure the authentication exchange through Actions.
Use the Credential workflow to create it. Credential is not an option alongside Outbound, Inbound, CSV Import and Email Handler in New Payload.
Configure the token request
Open the generated Payload and select HTTP Request. Review Request Settings, including the authentication endpoint, method, content type, timeout and any Credential required by the token call itself.
Configure Body, Headers and Parameters according to the provider's token contract. Depending on that contract, the request can contain a grant type, client identifier, client secret, refresh token or scope.
Use the generated credential mappings where appropriate and keep sensitive values in Credential configuration. Add a preceding Query only if the authentication flow actually needs Salesforce data.
Model the token response
Select HTTP Response and set its expected Content Type and response Policy. Model the returned values needed to maintain the Credential, such as access token, refresh token and expiry information.
HTTP Request and HTTP Response remain consecutive. A successful status does not prove that the body contains all the values required for the credential update.
Review the generated Target
Select the Target after HTTP Response. Confirm that it identifies the intended Credential and maps the returned values into the correct fields.
Use Payload Data from HTTP Response for response-derived values, and review any expiry conversion required by the provider. Keep the generated credential-update behaviour focused because business Payloads may immediately depend on the refreshed value.
The generated refresh sequence has special runtime handling. It does not establish a general no-commit execution pattern for arbitrary Targets or Flows.
Test refresh and subsequent use
Run a controlled refresh using the appropriate test credentials, inspect the Job and confirm the intended Credential fields were updated. Then test a business Outbound Payload using that Credential.
Include an authentication failure case and confirm that the response policy and Job make the failure visible. Avoid exposing token values in shared screenshots or support extracts.
