Gearset uses OAuth 2.0 for the majority of its integrations, including Salesforce, GitHub, GitLab, Bitbucket Cloud, Azure DevOps, ServiceNow, and Asana.
β
For Salesforce specifically, we use OAuth 2.0 with PKCE (Proof Key for Code Exchange), which adds an extra layer of security to the authorization flow.
β
Two integrations currently use OAuth 1.0a with RSA-SHA1 signing:
Bitbucket Data Center β the platform supports OAuth 2.0, but Gearset hasn't migrated yet
Jira Server / Data Center β migration to OAuth 2.0 is in progress
