Skip to main content

Summary

A relay is a small web service between TruAgents and Salesforce. TruAgents sends the hot lead to the relay. The relay logs in to Salesforce and creates or updates the Lead. Simple version: TruAgents only knows the relay’s URL and a token that opens the relay. The Salesforce credentials stay in your relay’s hosting, never in TruAgents. Why teams pick a relay:
  • No third-party automation tool sees your leads.
  • The relay answers TruAgents after Salesforce responds, so a Salesforce outage makes TruAgents retry automatically.
  • The Lead is upserted on the TruAgents contact id, so retries and repeat messages never create duplicates.
This guide is step 2 of Send hot leads to Salesforce. Build the TruAgents workflow first.

Who this is for

A developer who can host a Node.js service, working with a Salesforce admin.

What you need

  • A host that gives the service a public https:// URL, for example a container platform, a serverless function with an HTTPS URL, or a VM behind a load balancer. TruAgents doesn’t deliver to http://, private, or internal addresses.
  • Node.js 18 or later. The relay has no dependencies.
  • A Salesforce admin for the one-time Salesforce setup.

Step 1: Salesforce setup (admin, one time)

1

Add the external id field

In Setup → Object Manager → Lead → Fields & Relationships, click New. Choose Text, length 64, label TruAgents Contact Id. Check that the API name is TruAgents_Contact_Id__c, and tick Unique and External ID.
2

Add the Lead Source value

In Object Manager → Lead → Fields & Relationships → Lead Source, add the picklist value TruAgents. If you’d rather use an existing value, change LeadSource in the relay code.
3

Create an app for the client credentials flow

In Setup, create a Connected App in App Manager, or an External Client App in External Client App Manager if your org uses those. Then:
  • Enable OAuth. Enter any callback URL, for example https://login.salesforce.com/services/oauth2/callback. The relay doesn’t use it.
  • Add the OAuth scope Manage user data via APIs (api).
  • Enable Client Credentials Flow.
  • In the app’s policies, set the Run As user for the client credentials flow. Use an integration user that can create and edit Leads and can edit TruAgents_Contact_Id__c.
4

Hand over the credentials

Copy the app’s Consumer Key and Consumer Secret, plus your My Domain URL (for example https://acme.my.salesforce.com). The client credentials flow requires the My Domain URL, not login.salesforce.com. Send these to the developer through your password manager, never by email or chat.

Step 2: deploy the relay (developer)

Save this as salesforce-relay.mjs:
salesforce-relay.mjs
Set these environment variables in your host’s secret store: Start it with node salesforce-relay.mjs. If a required variable is missing, the relay refuses to start and names the variable.

How the relay answers TruAgents

The relay’s status code tells TruAgents what to do next: Every request is logged with the TruAgents event id, the run id, and the Salesforce status. When Salesforce rejects a Lead, its error message is logged too.

Step 3: test the relay before connecting TruAgents

Save the example body from the Webhooks reference as payload.json, then:
Replace https://relay.example.com/ with your relay’s URL. Delete the test Lead afterwards.

Step 4: connect TruAgents

  1. Open the workflow and click the Send webhook step.
  2. Endpoint URL: the relay’s https:// URL.
  3. Headers: click Add header. Name X-Relay-Token, value the RELAY_TOKEN.
  4. Click Save workflow, then continue with Step 3: test and go live.
Anyone in your organization who can open the workflow can read the X-Relay-Token value. That’s why it must only open the relay. Never put the Salesforce Consumer Secret or a Salesforce password in a header. Rotate RELAY_TOKEN when people with workflow access leave, and update the header at the same time.

Running it

  • Alerts. Alert on any 400 or 401 the relay returns: those leads don’t reach Salesforce and TruAgents won’t retry them. Also alert on repeated 503s.
  • Personal data. The relay handles names, emails, phone numbers, and message previews. Host it where your company’s data policies allow, and keep log retention short.
  • Changing the mapping. Edit toSalesforceLead. To also create a Task for each hot message, add a second Salesforce call after the upsert.