Salesforce Decode
Salesforcedecode
Back to questions
Headless 360Intermediateslasauthcommerceoauth

Implement SLAS authentication for headless shoppers

Real World Scenario

Mobile app guest checkout works but registered login fails intermittently with token expiry errors during long browsing sessions.

Expected Answer

• Understand SLAS guest vs registered token lifetimes and refresh token flows • Implement proactive token refresh before expiry on client side • Secure storage of refresh tokens in mobile keychain—not localStorage on web • Handle passwordless and social login flows per B2C Commerce identity config • Basket merge logic when guest converts to registered mid-session • Monitor auth error rates by app version and OS • Document token revocation on logout and device theft scenarios

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Direct answer: Understand SLAS guest vs registered token lifetimes and refresh token flows Also consider: Implement proactive token refresh before expiry on client side In practice: Secure storage of refresh tokens in mobile keychain—not localStorage on web Balance speed of delivery with maintainability.

Architect Perspective

Auth bugs become cart abandonment—architects prioritize auth flow telemetry as highly as checkout funnel metrics.