Articles / Strategy
Strategy

Important Updates to Legal Terms for Salesforce APIs: How This Impacts Your SaaS Business

For years, SaaS vendors have connected directly to Salesforce orgs via OAuth without ever signing a partner agreement, reasoning that customer consent was enough. Salesforce's updated API Terms and Developer MSA make clear that was never true, and now spell out exactly who must enrol in the AppExchange Partner Program to keep their API access.

Jerry Huang
Jerry Huang
26 July 2026
Important Updates to Legal Terms for Salesforce APIs: How This Impacts Your SaaS Business

For years, software companies have built platforms outside of Salesforce and connected them directly to customer orgs without ever signing an agreement with Salesforce.

The line of thinking went something like this: our customers own their Salesforce data, and they gave us permission via OAuth, so our integration is free to run and we don’t owe Salesforce anything or need to join their partner program.

That has never actually been okay, but it was not entirely clear. Salesforce has updated its API License and Terms of Service and Developer Main Services Agreement (Developer MSA) to make this explicit.

The New Bottom Line

Using Salesforce tech means signing Salesforce terms. If you have an app or software platform that makes Salesforce API calls, you are consuming Salesforce technology and platform infrastructure. Accepting these API terms is mandatory, and customer OAuth consent does not bypass them.

Commercial apps must pay to play. In most cases, if yours is a commercial app (that is, you charge your customers for access to your software or services), you are required to enrol in the Salesforce AppExchange Partner Program. This means paying Salesforce for the right to use that service and interface with their ecosystem.

Data Access vs Platform Access: The Core Distinction

Salesforce’s updated legal framework explicitly separates access into two distinct boundaries.

Customer data access (Customer MSA). Your end customer owns their CRM data. When they log into your app and click “Allow” on an OAuth screen, they are only authorising you to access their data.

Platform and API access (API Terms and Developer MSA). The underlying infrastructure, schemas, and API endpoints belong to Salesforce. Your end customers do not have the legal authority to grant you permission to use Salesforce’s backend technology. Only Salesforce can do that.

The moment your application’s servers make a call to a Salesforce endpoint, your company enters into a direct contract with Salesforce.

Who Must Enrol in the Partner Program?

Salesforce’s terms explicitly define who needs a formal partner agreement:

Integration scenarioRequirement
Commercial multi-tenant app - you charge customers for a SaaS tool that connects to SalesforcePartner agreement required: you must join the AppExchange Partner Program and pay revenue or program fees for the right to commercially interface with Salesforce.
Bespoke custom code - an SI or consulting firm building custom, single-org code for one clientExempt: operates directly under that specific client’s enterprise agreement.
Free utilities and tools - software offered completely at no cost, with no monetisation anywhereLimited exception: free apps are not required to pay partner revenue-share fees, but are still strictly bound by the API Terms and Developer MSA.

Watch the freemium trap. Both agreements define a “Commercial Product” as any application where installation, access, or use, of any version or feature, requires payment of fees of any kind, and both say explicitly that a freemium payment model counts. If your app has a paid tier, a paid add-on, or any upsell path at all, it is a Commercial Product under Salesforce’s terms, and using the APIs to run it is Commercial Use requiring ISV Partner Program enrolment, even if most users never pay. Only an app with no paid tier anywhere, ever, sits outside that requirement.

Action Plan for Software Vendors

If your product connects to Salesforce orgs via OAuth without a formal partner agreement, take these steps immediately:

  • Evaluate your commercial model. If your software generates revenue and connects to multiple customer orgs using standard APIs, acknowledge that continuing to run off-market puts your API access at risk.
  • Apply to the Salesforce AppExchange Partner Program. Formalise your integration by enrolling as an ISV partner to secure the legal right to build, authenticate, and commercialise multi-tenant integrations.
  • Review your end-user legal agreements. Make sure your customer contracts clearly state that while customers provide data access via their Salesforce subscription, your software independently complies with Salesforce’s API and developer terms.

If you’re navigating the AppExchange Partner Program for the first time, see Mastering the AppExchange Security Review for what comes after enrolment, and Packaging External Client Apps in 2GP for the OAuth mechanics of building a compliant integration.

Need a hand?
Not sure your Salesforce setup is configured correctly?

We'll audit your architecture, security, and integration posture.

Book an audit

Share this article

Jerry Huang
Written by
Jerry Huang

Jerry Huang is the Founder & CEO of Sliick. He is passionate about building apps, helping customers succeed, and starting and scaling great businesses with the Salesforce platform. Jerry has been in tech for over two decades. He has 30 Salesforce certifications, including the Salesforce Certified Technical Architect, and an approved U.S. patent.

Keep reading