Skip to main content

Set up the Salesforce file connection for CSV imports

Configure the authenticated Salesforce file connection and permissions required by CSV imports.

Set up the Salesforce file connection for CSV imports

Use a Salesforce file connection for imports started from Flow. Configure the connection once, then enter its Named Credential API name on each CSV Import Payload. For the manual upload or existing-file workflow, see Run a CSV import; the supported session fallback can be used when no file connection is configured.

Every import started from Flow requires this connection, including screen, record-triggered and unattended Flows.

Configure authentication and the endpoint

Create an OAuth-authenticated Named Credential connected to an External Credential. Point it to the org's HTTPS My Domain origin, such as https://example.my.salesforce.com, without a REST path.

For unattended imports, use a named principal authenticated as a dedicated API-enabled user that can access the source files. Configure token renewal through the External Credential. Follow Salesforce's Named Credentials setup and OAuth credential guidance.

Use an API name such as PayloadsSalesforceFiles. For a subscriber-created Named Credential, add pylds to its allowed namespaces so the installed package can use it. Salesforce documents this in Package Named Credentials.

Grant access to the actual execution identities

Grant the user that runs the Flow access to the External Credential principal and the required User External Credentials permissions. Include Automated Process or the configured workflow user when that is the Flow's actual execution identity.

Also grant that identity Payloads runtime permissions and access to the source file. The authenticated connection principal must be able to download the same file.

These are separate access checks. A principal that can download the file does not remove the invoking user's local file-access requirements. It also does not become the user under whom Target Actions execute.

Permissions assigned only to the person designing the Flow do not establish unattended runtime access.

Connect the Payload

  1. Open the CSV Import Payload and select CSV Import.

  2. Select Edit CSV settings.

  3. In Salesforce file connection, enter the Named Credential API name.

  4. Save the settings.

Enter the API name only. Do not paste a URL, access token or Salesforce session ID into this field.

CSV Settings provides a Salesforce file connection field for the Named Credential API name.

The field is blank in the manual demo. This shows where a Flow connection is configured; it does not show an authenticated connection.

Verify the complete path

Run a small import as the intended user, then test each actual Flow context that will start imports. Check both Queueable and Batchable if both will be used.

If a worker cannot read the file, check the connection's authentication, principal access, allowed namespace and file visibility for both identities. Starting successfully does not prove that later byte-range file reads will succeed.

The manual runner has a conditional session-based fallback when no connection is configured. It requires an active Remote Site Setting for the org origin and an API-capable session. Use the configured file connection for repeatable operation, especially for Flow and unattended execution.

Did this answer your question?