Pardot Integration Permissions

Oktopost integrates with Pardot (Marketing Cloud Account Engagement) using Salesforce OAuth 2.0. When the integration is connected, Oktopost reads prospect data from your business unit and can log social link clicks as webpage visits in Pardot.

This article outlines the minimum user and OAuth requirements for the integration to function, as well as Pardot role abilities grouped by feature.

User Requirements

  • A single sign-on (SSO) enabled Salesforce user with access to the target Account Engagement business unit. The user must be able to sign in to Account Engagement through Salesforce.
  • A valid Business Unit ID (18 characters, begins with 0Uv) for the business unit you connect in Oktopost.
  • An Oktopost user with permission to manage integrations (create or update integrations in Settings > General > Integrations).
  • A configured CNAME in Oktopost. A CNAME is required to complete Pardot integration setup and to track social link clicks.

Salesforce OAuth Requirements

Oktopost authenticates to Account Engagement through Salesforce OAuth. Your Salesforce admin must allow the Oktopost connected app to access Account Engagement API services.

Requirement Required Purpose
pardot_api OAuth scope on the connected app Allows Oktopost to call Account Engagement API endpoints using a Salesforce access token
SSO-enabled integration user Account Engagement API requires a Salesforce user who can access Account Engagement through SSO
Pardot-Business-Unit-Id header value Routes API requests to the correct business unit during setup and sync

If OAuth authorization fails, confirm the connected app includes the Access Pardot services (pardot_api) scope and that the authorizing user is SSO enabled for Account Engagement. See Salesforce Account Engagement API authentication for details.

Pardot Role Abilities

API access is governed by the Account Engagement role assigned to the Salesforce user who authorizes the integration. Required abilities depend on which Oktopost features you use.

Pardot Ability Required Purpose in Oktopost
Marketing > Campaigns > View Lists and reads tracking campaigns during integration setup
Prospects > Prospects > View Imports prospect records into Oktopost on a scheduled basis for lead matching

Current Oktopost Pardot integrations use Salesforce OAuth (version 3). They do not call the Account Engagement Visitor API. You do not need Prospects > Visitors > View for standard setup, click tracking, or scheduled lead import.

Feature-Specific Requirements

Track Social Clicks

Social click tracking uses your Oktopost CNAME and the Pardot tracking campaign you select during setup. Clicks appear in Pardot as webpage visits with UTM parameters appended by Oktopost.

This workflow uses Pardot's client-side tracking script on your Oktopost CNAME. It does not require ongoing Account Engagement API calls after setup. You still need Marketing > Campaigns > View to select the tracking campaign during configuration.

Lead Import and Matching

Oktopost pulls prospect data from Account Engagement on a scheduled basis and matches it to social activity in your account. This requires Prospects > Prospects > View on the integration user's Account Engagement role.

If lead matching fails but social clicks appear in Pardot, confirm the integration user can view prospects and that the integration completed OAuth authorization successfully.

Social Activities from Salesforce

Syncing full social engagement activities (likes, shares, comments) into Pardot requires the Oktopost Salesforce integration with the Social Insights package, plus a custom object sync from Salesforce to Pardot. This path requires Pardot Advanced Edition or an add-on in Pardot Plus Edition. See How to Set Up the Pardot (MCAE) Integration for details.

This workflow uses the Salesforce integration, not the Pardot API directly.

Setup Notes

  1. Confirm the authorizing Salesforce user is SSO enabled and assigned a role with campaign and prospect view abilities.
  2. In Salesforce Setup, search for Business Unit Setup or Pardot Account Setup in the Quick Find box, then copy the 18-character Business Unit ID for the unit you want to connect.
  3. In Oktopost, go to Settings > General > Integrations, add Pardot or Pardot Sandbox, enter the Business Unit ID, and complete Salesforce OAuth authorization.
  4. Select the Pardot tracking campaign and CNAME, then save the integration settings.

Helpful Tips

  • Use a dedicated integration user rather than a personal admin account so permissions stay consistent if individual users change roles.
  • If campaign search fails during setup, verify the user role includes Marketing > Campaigns > View.
  • If lead matching fails but clicks appear in Pardot, confirm the integration user can view prospects and that OAuth authorization completed successfully.
  • Lead data is pulled on a scheduled basis. See Data Fetching Frequency for CRM and MA Integrations for sync timing.
Was this article helpful?
0 out of 0 found this helpful