Install the Kemicard managed package from the Salesforce AppExchange, authorize the backend, and get your org provisioned for Apple Wallet and Google Wallet. Time required: about 45 minutes plus provisioning turnaround. The Kemicard managed package install takes about 15 minutes; this guide shows how to install Kemicard (AppExchange listing) end to end.
Prerequisites
- A Salesforce org (Sales Cloud, Service Cloud, Nonprofit Cloud, NPSP, or compatible) with System Administrator access.
- Your production and sandbox Org IDs — required to provision licenses on the Kemicard backend. If an org is refreshed or changed, the Org ID changes and provisioning must be updated.
- A dedicated integration mailbox for the named credential user. Prefer a shared system-admin mailbox with non-expiring credentials over a personal account — this address also receives system alerts.
- A decision on which production user acts as the integration user. Enrollment emails send from this identity, so choose a branded, monitored address.
Step 1 — Locate Kemicard on the Salesforce AppExchange
The installation begins at the official Kemicard listing on the Salesforce AppExchange, the official marketplace for Salesforce applications.
- Navigate to the Kemicard listing on the Salesforce AppExchange.
- Click Get It Now and log in with your Salesforce or Trailblazer account.

- Confirm your details and select the checkbox to agree to the terms and conditions.

- Initiate the external installation: click Visit Provider. This redirects you to the provider's official installation website, where the installation process is managed.

Step 2 — Initiate the installation for your sandbox
After being redirected to the installation portal (usually install.kemicard.app), carefully select the product and make sure the installation targets a non-production environment.
- Select the product for Salesforce: on the installation landing page, explicitly click “Kemicard digital wallet membership pass for Salesforce” to confirm you are installing the correct integration for your Salesforce instance.

- Review package details: click the “Kemicard view details” link for comprehensive product documentation, release notes, security information, and feature lists — review thoroughly before installing.
- Start the login and installation flow: click the prominent Login to install button to initiate the secure connection and authentication with Salesforce.

Step 3 — Choose the environment (sandbox recommended)
When prompted to choose a destination for the package, we highly recommend installing in a Sandbox or Scratch Org for your initial evaluation. Beyond standard testing best practice, the installation creates unpackaged metadata (custom fields, settings, logs) that remains in the org even after the package is uninstalled. Testing in a sandbox keeps production clean and avoids tedious manual cleanup of these auxiliary components later.
Step 4 — Authenticate
- Enter your sandbox credentials (username and password) to authenticate your account.
- Click Login to sandbox.
- Grant permissions: click Allow so the installation can proceed.

Step 5 — Install the package
- After authentication you are redirected back to the installation portal — switch back to the
install.kemicard.appwebsite. - Click Install to begin deployment.

Once the process initiates, you can click “view” or open a new window to access the Salesforce org where Kemicard is being installed.

Step 6 — Verify the installation
- In your Salesforce sandbox, click Setup to open the configuration menu.
- In the Quick Find search box, enter “installed packages” and click Installed Packages.
- Confirm that Kemicard appears and matches the version number you selected on the portal.

Step 7 — Update the named credential
- In the Quick Find box, enter “Named Credentials” and click Named Credentials.
- Locate and click “Kemicard app” to view its details.

- Click Edit to modify the settings.

- Update the authentication details: click the username field and enter the username and password from your credentials email to update the credential securely.

- Click Save to apply the changes.

Most “pass URLs not generating” issues are authentication failures here — see Troubleshooting for status-code diagnosis (401 vs 409).
Step 8 — Authorize the Kemicard app
The final installation stage authorizes the application inside the Salesforce user interface.
- Open the App Launcher (the grid icon, top left).
- Search for the app: type “Kemicard” in the search box.
- Launch the application: click Kemicard.
- Access the console: click the Kemicard Console tab to open the main management interface.

- Authorize the user: click Authorize Kemicard user to initiate the permission grant.

- Confirm access: you are redirected to a Salesforce authorization page — click Allow to finalize the authorization and complete the installation.


Step 9 — Configure email deliverability
- Verify your sending domain and set up DKIM for production sends.
- In sandboxes and scratch orgs with unverified domains, enable “Use a substitute email address for unverified domains” under Email Deliverability, or provision a DKIM key in DNS for the sandbox.
- Send a test enrollment email to multiple mail providers; check quarantine folders if a trial email doesn't arrive.
Step 10 — Generate your first pass
With installation complete, prove the pipeline end to end: the Getting Started guide walks you through generating and sending your first membership pass, step by step with screenshots — then change a mapped field and watch the installed pass update on a real device.
Alternative: guided install via MetaDeploy
Kemicard can also be installed through Kemisoft's MetaDeploy installer, which automates package installation and optional sample data:
- Navigate to the Kemisoft MetaDeploy products page.
- Click the user icon (top right) and log in with the org — sandbox or production — you intend to install into.
- Select the Kemicard tile, click Kemicard — View Details, then Install and wait for completion.
- Verify under Setup → Installed Packages that Kemicard Digital Pass is installed.
- Open the App Launcher → Kemicard (as a System Administrator or Integration User), go to Kemicard Configuration, click Authorize Kemicard User, and click Allow on the OAuth popup. A success screen confirms authentication.
The MetaDeploy products page lists the Kemicard installers — pick the product tile matching your edition:

After you choose the plan and log in, MetaDeploy runs each installation step automatically and shows live progress:

When the run finishes, confirm the result in Setup exactly as with the AppExchange path:

Finish by authorizing the integration user from the Kemicard Configuration tab:

Template Pass configuration — field reference
After installation, open the Template Pass tab. A sample template, Woofly Membership Pass, ships with the package for reference. The key fields:
| Field | What to enter |
|---|---|
| Name | The template pass name |
| Record Type | The record type name |
| Organization Name | Your company name |
| Email Template | API name of the email template used to send Apple passes to users |
| Background Color | RGB value for the pass background |
| Update Email Template | Developer name of the email template used when a Google Wallet pass is updated |
| From Email Address / ID | Sender address for outbound emails and the Organization-Wide Email Address ID |
Google Wallet fields
| Field | Purpose |
|---|---|
| Card Title | Header of the pass — usually the business name. Required; appears in the header row at the very top. |
| Header | The pass title. Required; appears in the title row of the detail view. |
| Subheader | Title label, such as where the pass can be used; appears above the title. |
| Language | Language of pass values. |
| Smart Tap | Conveys data between the device and an NFC terminal. |
| State | Controls display: inactive objects move to the wallet's "Expired passes" section; default is ACTIVE. |
| Logo URL | Shown top-left in the detail view and on the thumbnail; without it, the first letter of the Card Title is used. |
| Detail Banner / Hero Image | Front-of-card imagery, displayed at 100% width. |
Apple Wallet fields
| Field | Purpose |
|---|---|
| Card Title | Text displayed next to the logo. |
| Description | Short description used by iOS accessibility technologies. |
| Expiration / Relevant Date | W3C timestamps (complete date with hours and minutes) controlling expiry and when the pass surfaces. |
| Foreground / Label / Strip Color | CSS-style RGB triples, e.g. rgb(100, 10, 110) — decimals are not supported. |
| Max Distance | Maximum distance in meters from a location at which the pass is relevant. |
| Sharing Prohibited | Removes the Share button on the back of the pass (iOS 11+). |
| Suppress Strip Shine | Displays the strip image without the shine effect (default true). |
| Grouping Identifier | Groups related event tickets/boarding passes in Wallet. |
| Wallet Resource ID | Content Document ID of a zip file containing all pass resources. |
If you installed with sample data, open the Template Pass tab to find the Woofly reference template — the fastest starting point for your own designs:

Open the template to see how the field reference above maps onto a real record — every row in the tables corresponds to a field here:

The Kemicard Configuration record holds org-wide settings, including the email template used for enrollment sends:

A successful authorization confirmation means the org is fully connected and ready to generate passes:

Wire up Flows or Triggers
Two methodologies activate pass generation (full details in the Flow Integration guide and Architecture reference):
- Salesforce Flow — a record-triggered Flow on the relevant object (e.g., Contact) with a decision element, calling the Generate Pass Apex Action with
configurationIdandwhatId(plustemplatePassIdto override the configuration's template binding); capture the returned Pass ID and write it back to the record. - Apex Trigger — call
AppleTemplatePassSFObjectDataService.upsertPassesfrom your trigger handler with a populatedPassRequest. IncludepassIdto update an existing pass instead of creating a new one.
Permission sets & user access
Kemicard ships permission sets that control who can design templates, generate passes, run bulk actions, and view pass records. Assign them deliberately:
| Role | Typical assignment | Can do |
|---|---|---|
| Kemicard Administrator | Salesforce admins | Templates, Configuration, named credential, bulk actions, licensing view |
| Kemicard Standard User | Membership / events staff | Generate passes, send messages from records, view pass status |
| Scanner User | Door and front-desk staff | Scan passes, record attendance and redemptions |
Object and field access always follows the running user's profile and permission sets — Kemicard never bypasses your sharing model.
Post-install checklist
- Named credential authenticates (generate a test pass URL)
- Email template set on the Configuration and a test enrollment email delivered
- Test pass installed on a physical iPhone and Android device
- Field change on the test record refreshes the installed pass
- Push notification received on both platforms
- Permission sets assigned to admin, staff, and scanner users
- Sandbox Org ID and production Org ID recorded with your account manager
Installation FAQ
- Do upgrades require reinstalling? No — upgrades install as new managed package versions over the top, preserving your templates and configuration.
- Can we install in a scratch org? Yes, for development. Note the email deliverability caveats above for unverified domains.
- Does a sandbox refresh break anything? A refresh changes the sandbox Org ID, so backend provisioning must be re-aligned — contact support with the new Org ID before testing resumes.
- What network access does the org need? Only outbound HTTPS from Salesforce to the Kemicard backend via the named credential; there are no inbound connections into your org.



