Gearset uses OAuth 2.0 for the majority of its integrations, including Salesforce, GitHub, GitLab, Bitbucket Cloud, Azure DevOps, ServiceNow, and Asana.
For Salesforce specifically, we use OAuth 2.0 with PKCE (Proof Key for Code Exchange), which adds an extra layer of security to the authorization flow.
Two integrations currently use OAuth 1.0a with RSA-SHA1 signing:
Bitbucket Data Center — the platform supports OAuth 2.0, but Gearset hasn't migrated yet
Jira Server / Data Center — migration to OAuth 2.0 is in progress
