Hardcoded callouts authentication

Overview

Named credentials make callouts much easier to maintain. For example, if an endpoint URL changes, named credentials allow updating it without any code changes. Furthermore, named credentials don’t need remote site settings, otherwise required for callouts to external sites via Apex.

Business Impact

Suboptimal resource allocation, increased costs, and delayed time-to-market for new features and products.

Resources

Very Frequent

Incidence

How common is this issue?
40%22%
arrow down18%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
1 year7 months
arrow down52%
shorter
BenchmarkWith Clayton

Frameworks

EasyiconIntentionaliconStrategyiconTechnical DebticonA05:2021 – Security Misconfigurationicon