Salesforce Decode
Salesforcedecode
Back to questions
IntegrationIntermediatemulesoftgovernanceconnected-app

Design MuleSoft API autodiscovery linked to Salesforce connected app governance

Real World Scenario

Fifty MuleSoft apps each created own connected app; security audit cannot map API traffic to business owner.

Expected Answer

• API Manager autodiscovery registers API to Anypoint Exchange • One connected app per API product not per MuleSoft worker • Client ID enforcement policy on all production APIs • Integration catalog links Exchange API connected app owner SLA • Automated connected app review quarterly disable orphan apps • SLA tier rate limit per API consumer • Certificate pinning for high-security APIs

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Main difference: use case and scale. API Manager autodiscovery registers API to Anypoint Exchange. One connected app per API product not per MuleSoft worker. Pick based on your integration pattern and team capability. Connected app sprawl equals credential sprawl—govern via API Manager autodiscovery catalog. Balance speed of delivery with maintainability.

Architect Perspective

Connected app sprawl equals credential sprawl—govern via API Manager autodiscovery catalog.