PO Box 55056 RPO Windermere, Edmonton, AB T6W 5B4, Canada

Installation Guide

Install the Kemicard managed package from the Salesforce AppExchange, authorize the backend, and get your org provisioned for Apple Wallet and Google Wallet. Time required: about 45 minutes plus provisioning turnaround. The Kemicard managed package install takes about 15 minutes; this guide shows how to install Kemicard (AppExchange listing) end to end.

Prerequisites

  • A Salesforce org (Sales Cloud, Service Cloud, Nonprofit Cloud, NPSP, or compatible) with System Administrator access.
  • Your production and sandbox Org IDs — required to provision licenses on the Kemicard backend. If an org is refreshed or changed, the Org ID changes and provisioning must be updated.
  • A dedicated integration mailbox for the named credential user. Prefer a shared system-admin mailbox with non-expiring credentials over a personal account — this address also receives system alerts.
  • A decision on which production user acts as the integration user. Enrollment emails send from this identity, so choose a branded, monitored address.
Provisioning is managed for you. Kemisoft provisions the Apple certificate and Google Wallet issuer setup during onboarding and tracks certificate renewals per client — no wallet developer accounts needed on your side.
Who implements? This guide is written for your internal Salesforce admin — but you can equally hand implementation to any of our SI partners or to the Kemisoft Professional Services team, which has implemented Kemicard on every Salesforce Cloud.
Free 30-day trial: choosing Get It Now on AppExchange starts a free 30-day trial of Kemicard in your sandbox — this guide is exactly the process to follow, and the Getting Started walkthrough takes you from installed package to your first live pass. Want to see it working before installing anything? Launch the Test Drive to explore a fully configured org first.

Step 1 — Locate Kemicard on the Salesforce AppExchange

The installation begins at the official Kemicard listing on the Salesforce AppExchange, the official marketplace for Salesforce applications.

  1. Navigate to the Kemicard listing on the Salesforce AppExchange.
  2. Click Get It Now and log in with your Salesforce or Trailblazer account.
Get It Now on the AppExchange listing — log in with your Salesforce or Trailblazer account
Get It Now on the AppExchange listing — log in with your Salesforce or Trailblazer account
  1. Confirm your details and select the checkbox to agree to the terms and conditions.
Confirm details and agree to the terms and conditions
Confirm details and agree to the terms and conditions
  1. Initiate the external installation: click Visit Provider. This redirects you to the provider's official installation website, where the installation process is managed.
Click Visit Provider to continue to the installation portal
Click Visit Provider to continue to the installation portal

Step 2 — Initiate the installation for your sandbox

After being redirected to the installation portal (usually install.kemicard.app), carefully select the product and make sure the installation targets a non-production environment.

  1. Select the product for Salesforce: on the installation landing page, explicitly click “Kemicard digital wallet membership pass for Salesforce” to confirm you are installing the correct integration for your Salesforce instance.
Select
Select "Kemicard digital wallet membership pass for Salesforce" on the installation portal
  1. Review package details: click the “Kemicard view details” link for comprehensive product documentation, release notes, security information, and feature lists — review thoroughly before installing.
  2. Start the login and installation flow: click the prominent Login to install button to initiate the secure connection and authentication with Salesforce.
Click Login to install to begin the authentication flow
Click Login to install to begin the authentication flow

Step 3 — Choose the environment (sandbox recommended)

When prompted to choose a destination for the package, we highly recommend installing in a Sandbox or Scratch Org for your initial evaluation. Beyond standard testing best practice, the installation creates unpackaged metadata (custom fields, settings, logs) that remains in the org even after the package is uninstalled. Testing in a sandbox keeps production clean and avoids tedious manual cleanup of these auxiliary components later.

Step 4 — Authenticate

  1. Enter your sandbox credentials (username and password) to authenticate your account.
  2. Click Login to sandbox.
  3. Grant permissions: click Allow so the installation can proceed.
Click Allow to grant the permissions the installer needs
Click Allow to grant the permissions the installer needs

Step 5 — Install the package

  1. After authentication you are redirected back to the installation portal — switch back to the install.kemicard.app website.
  2. Click Install to begin deployment.
Click Install to begin deploying the managed package
Click Install to begin deploying the managed package

Once the process initiates, you can click “view” or open a new window to access the Salesforce org where Kemicard is being installed.

Installation in progress — open the target org in a new window to watch
Installation in progress — open the target org in a new window to watch
Going to production? When your sandbox is validated, follow the Production Install & Migration Guide — including credential provisioning, migration order, and the required Console upgrade steps.
Restricted production access? If your policies prevent vendor access to production, install the managed package yourself and receive client-specific components via change sets. Get the app installed in production before the change set is built.

Step 6 — Verify the installation

  1. In your Salesforce sandbox, click Setup to open the configuration menu.
  2. In the Quick Find search box, enter “installed packages” and click Installed Packages.
  3. Confirm that Kemicard appears and matches the version number you selected on the portal.
Setup → Installed Packages — confirm Kemicard and its version number
Setup → Installed Packages — confirm Kemicard and its version number

Step 7 — Update the named credential

  1. In the Quick Find box, enter “Named Credentials” and click Named Credentials.
  2. Locate and click “Kemicard app” to view its details.
Setup → Named Credentials → Kemicard App
Setup → Named Credentials → Kemicard App
  1. Click Edit to modify the settings.
Click Edit on the Kemicard App named credential
Click Edit on the Kemicard App named credential
  1. Update the authentication details: click the username field and enter the username and password from your credentials email to update the credential securely.
Trial credentials on request. Trial named-credential access is issued per organization: request it with the form below and our team will email your credentials. Trial credentials are valid for 30 days; permanent production access is issued during your formal onboarding.

Request Trial Credentials

Business email required — generic providers (Gmail, Hotmail, Yahoo, etc.) are not accepted. Credentials are sent to the address you provide.

Enter the trial username and password on the named credential
Enter the trial username and password on the named credential
  1. Click Save to apply the changes.
Save the updated named credential
Save the updated named credential

Most “pass URLs not generating” issues are authentication failures here — see Troubleshooting for status-code diagnosis (401 vs 409).

Step 8 — Authorize the Kemicard app

The final installation stage authorizes the application inside the Salesforce user interface.

  1. Open the App Launcher (the grid icon, top left).
  2. Search for the app: type “Kemicard” in the search box.
  3. Launch the application: click Kemicard.
  4. Access the console: click the Kemicard Console tab to open the main management interface.
App Launcher → Kemicard → Kemicard Console
App Launcher → Kemicard → Kemicard Console
  1. Authorize the user: click Authorize Kemicard user to initiate the permission grant.
Click Authorize Kemicard user in the Kemicard Console
Click Authorize Kemicard user in the Kemicard Console
  1. Confirm access: you are redirected to a Salesforce authorization page — click Allow to finalize the authorization and complete the installation.
Click Allow on the Salesforce authorization page
Click Allow on the Salesforce authorization page
Authorization complete — Kemicard is installed and connected
Authorization complete — Kemicard is installed and connected

Step 9 — Configure email deliverability

  • Verify your sending domain and set up DKIM for production sends.
  • In sandboxes and scratch orgs with unverified domains, enable “Use a substitute email address for unverified domains” under Email Deliverability, or provision a DKIM key in DNS for the sandbox.
  • Send a test enrollment email to multiple mail providers; check quarantine folders if a trial email doesn't arrive.

Step 10 — Generate your first pass

With installation complete, prove the pipeline end to end: the Getting Started guide walks you through generating and sending your first membership pass, step by step with screenshots — then change a mapped field and watch the installed pass update on a real device.

Test on real devices. Always validate templates with sample records on physical iPhones and Android phones before rollout — wallet rendering differs from the preview in edge cases.

Alternative: guided install via MetaDeploy

Kemicard can also be installed through Kemisoft's MetaDeploy installer, which automates package installation and optional sample data:

  1. Navigate to the Kemisoft MetaDeploy products page.
  2. Click the user icon (top right) and log in with the org — sandbox or production — you intend to install into.
  3. Select the Kemicard tile, click Kemicard — View Details, then Install and wait for completion.
  4. Verify under Setup → Installed Packages that Kemicard Digital Pass is installed.
  5. Open the App Launcher → Kemicard (as a System Administrator or Integration User), go to Kemicard Configuration, click Authorize Kemicard User, and click Allow on the OAuth popup. A success screen confirms authentication.
Sample data: selecting the "Sample Data" option during install ships the Woofly Membership Pass reference template plus five example flows (see the Flow Integration guide) — the fastest way to explore a working configuration.

The MetaDeploy products page lists the Kemicard installers — pick the product tile matching your edition:

Kemisoft MetaDeploy installer showing the Kemicard product tile
The Kemisoft MetaDeploy installer with the Kemicard product tile.

After you choose the plan and log in, MetaDeploy runs each installation step automatically and shows live progress:

Kemicard installation progress in MetaDeploy
Installation steps running in MetaDeploy — each component deploys and verifies in sequence.

When the run finishes, confirm the result in Setup exactly as with the AppExchange path:

Salesforce installed packages showing Kemicard Digital Pass
Setup → Installed Packages — Kemicard Digital Pass listed after a MetaDeploy install.

Finish by authorizing the integration user from the Kemicard Configuration tab:

Authorize Kemicard User button in the Kemicard Configuration tab
The Authorize Kemicard User button in the Kemicard Configuration tab completes the OAuth grant.

Template Pass configuration — field reference

After installation, open the Template Pass tab. A sample template, Woofly Membership Pass, ships with the package for reference. The key fields:

FieldWhat to enter
NameThe template pass name
Record TypeThe record type name
Organization NameYour company name
Email TemplateAPI name of the email template used to send Apple passes to users
Background ColorRGB value for the pass background
Update Email TemplateDeveloper name of the email template used when a Google Wallet pass is updated
From Email Address / IDSender address for outbound emails and the Organization-Wide Email Address ID

Google Wallet fields

FieldPurpose
Card TitleHeader of the pass — usually the business name. Required; appears in the header row at the very top.
HeaderThe pass title. Required; appears in the title row of the detail view.
SubheaderTitle label, such as where the pass can be used; appears above the title.
LanguageLanguage of pass values.
Smart TapConveys data between the device and an NFC terminal.
StateControls display: inactive objects move to the wallet's "Expired passes" section; default is ACTIVE.
Logo URLShown top-left in the detail view and on the thumbnail; without it, the first letter of the Card Title is used.
Detail Banner / Hero ImageFront-of-card imagery, displayed at 100% width.

Apple Wallet fields

FieldPurpose
Card TitleText displayed next to the logo.
DescriptionShort description used by iOS accessibility technologies.
Expiration / Relevant DateW3C timestamps (complete date with hours and minutes) controlling expiry and when the pass surfaces.
Foreground / Label / Strip ColorCSS-style RGB triples, e.g. rgb(100, 10, 110) — decimals are not supported.
Max DistanceMaximum distance in meters from a location at which the pass is relevant.
Sharing ProhibitedRemoves the Share button on the back of the pass (iOS 11+).
Suppress Strip ShineDisplays the strip image without the shine effect (default true).
Grouping IdentifierGroups related event tickets/boarding passes in Wallet.
Wallet Resource IDContent Document ID of a zip file containing all pass resources.

If you installed with sample data, open the Template Pass tab to find the Woofly reference template — the fastest starting point for your own designs:

Kemicard Template Pass tab with the Woofly sample template
The Template Pass tab with the Woofly sample template installed.

Open the template to see how the field reference above maps onto a real record — every row in the tables corresponds to a field here:

Kemicard template pass configuration fields
Template Pass field configuration — the field-reference tables above, as they appear on a real template.

The Kemicard Configuration record holds org-wide settings, including the email template used for enrollment sends:

Kemicard configuration screen
The Kemicard Configuration screen — org-wide settings including the enrollment email template.

A successful authorization confirmation means the org is fully connected and ready to generate passes:

Successful Kemicard authorization confirmation
Successful authorization — the org is connected to the Kemicard Server.

Wire up Flows or Triggers

Two methodologies activate pass generation (full details in the Flow Integration guide and Architecture reference):

  • Salesforce Flow — a record-triggered Flow on the relevant object (e.g., Contact) with a decision element, calling the Generate Pass Apex Action with configurationId and whatId (plus templatePassId to override the configuration's template binding); capture the returned Pass ID and write it back to the record.
  • Apex Trigger — call AppleTemplatePassSFObjectDataService.upsertPasses from your trigger handler with a populated PassRequest. Include passId to update an existing pass instead of creating a new one.

Permission sets & user access

Kemicard ships permission sets that control who can design templates, generate passes, run bulk actions, and view pass records. Assign them deliberately:

RoleTypical assignmentCan do
Kemicard AdministratorSalesforce adminsTemplates, Configuration, named credential, bulk actions, licensing view
Kemicard Standard UserMembership / events staffGenerate passes, send messages from records, view pass status
Scanner UserDoor and front-desk staffScan passes, record attendance and redemptions

Object and field access always follows the running user's profile and permission sets — Kemicard never bypasses your sharing model.

Post-install checklist

  • Named credential authenticates (generate a test pass URL)
  • Email template set on the Configuration and a test enrollment email delivered
  • Test pass installed on a physical iPhone and Android device
  • Field change on the test record refreshes the installed pass
  • Push notification received on both platforms
  • Permission sets assigned to admin, staff, and scanner users
  • Sandbox Org ID and production Org ID recorded with your account manager

Installation FAQ

  • Do upgrades require reinstalling? No — upgrades install as new managed package versions over the top, preserving your templates and configuration.
  • Can we install in a scratch org? Yes, for development. Note the email deliverability caveats above for unverified domains.
  • Does a sandbox refresh break anything? A refresh changes the sandbox Org ID, so backend provisioning must be re-aligned — contact support with the new Org ID before testing resumes.
  • What network access does the org need? Only outbound HTTPS from Salesforce to the Kemicard backend via the named credential; there are no inbound connections into your org.