SF API Explorer
Overview
Generate OpenAPI from a Salesforce org using your browser session.
SF API Explorer generates an OpenAPI 3.1 document from a Salesforce org you are already logged into in Chrome. Browse sObjects, query, composite, Bulk, Tooling, UI API, and Apex REST, try real calls against the org, and download YAML or JSON. WHAT IT DOES • Discovers the org’s REST surface and builds an OpenAPI 3.1 spec in the browser • Lists standard and custom sObjects, Query & Search, Composite, Apex REST, and other APIs (GraphQL, Bulk 2.0, Tooling, UI API, Limits when the org supports them) • Lets you filter by sObject, path, or HTTP method • Describes sObject fields on demand, then includes those schemas in the download • Lets you try GET, POST, PATCH, and DELETE against the selected org • Exports OpenAPI as YAML or JSON, with a Bearer token scheme pointed at the org instance URL • Works from your existing Salesforce session. If the org blocks cookie API access, you can sign in with a Connected App instead HOW TO USE IT 1. Log in to a Salesforce org in Chrome (prefer a Sandbox). 2. Click the SF API Explorer icon and choose that org. 3. Generate OpenAPI, then search or filter the catalog. 4. Open an operation to inspect it or send a try-it request. 5. Download YAML or JSON when you are ready to use the spec elsewhere. PERMISSIONS The extension only talks to Salesforce hosts. It needs: • Cookies — to use the session of orgs you are already logged into (the sid cookie is HttpOnly) • Tabs — to list open Salesforce tabs in the org picker • Identity — optional Connected App login when the session cookie cannot call the API • Storage — session-scoped OAuth tokens if you use Connected App login • Host access to *.salesforce.com, *.force.com, *.cloudforce.com, *.salesforce.mil, and *.salesforce-setup.com — to call REST and Tooling APIs directly PRIVACY • API calls go from this extension to your Salesforce org. They do not pass through a remote proxy. • Generated specs stay in this browser (IndexedDB). • Session IDs stay in memory. Connected App tokens stay in chrome.storage.session until the browser is closed. • The extension does not send your org data to the author. IMPORTANT Prefer a Sandbox. Generating and describing endpoints uses the org’s Salesforce API allocation. Try-it-out sends real REST calls, including writes and deletes. You are responsible for the org you use and any effect on data, limits, or security. The generated spec is best-effort and may be incomplete. Not affiliated with Salesforce. Salesforce is a trademark of Salesforce, Inc.
0 out of 5No ratings
Details
- Version0.1.0
- UpdatedSeptember 16, 2026
- Offered byNiklas F.
- Size213KiB
- LanguagesEnglish
- Developer
Email
mail@nfunk.dev - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes