Salesforce7 min read

Salesforce AppExchange: What It Is, Pricing and How to List

What the Salesforce AppExchange is, how app pricing works, how to install an app safely, and how to list your own: security review, 2GP and licensing.

The Salesforce AppExchange is Salesforce’s official marketplace: the place to find, evaluate and install apps, components, pre-built integrations, AI agents and consulting partners that extend Salesforce. Most Salesforce customers use at least one AppExchange app, and for many orgs it is the main way the platform gets extended for a specific business problem. This guide covers what is on it, how pricing works, how to install an app safely, and what it takes to publish one.

What is the Salesforce AppExchange?

The AppExchange is where companies find third-party solutions that run on or integrate with Salesforce. It is less like a phone app store and more like an enterprise procurement catalog: listings range from a single Lightning component you drop onto a page to full applications with their own data model, automation and user interface.

What sets it apart from a typical SaaS marketplace is Salesforce’s security review. Every app listed publicly, free or paid, has passed it before the listing goes live, so the bar is meaningfully higher than on most marketplaces.

What is on it: apps, components, agents and consultants

  • Apps. Full packages installed into your org, from document generation and CPQ tools to industry add-ons.
  • Components. Reusable Lightning components: kanban boards, enhanced lookups, signature capture.
  • Flow actions and templates. Extensions to Salesforce automation that do not need a full app.
  • Agents and agent actions. Listed through AgentExchange, the part of the marketplace for Agentforce: pre-built agents, topics and actions that an agent can invoke.
  • Consultants. Salesforce consulting partners, with their certifications, specialisations and customer reviews.

How AppExchange pricing works for buyers

There is no single pricing model, which is both a strength and a source of confusion.

  • Free. Genuinely free, though some are freemium with paid tiers for advanced features. Many components and utilities sit here.
  • Per user, per month. Like most SaaS: you pay for each Salesforce user who needs the app. The most common model for full applications.
  • Per org. A flat monthly or annual fee regardless of user count, usually better value for large teams.
  • Contact for pricing. Enterprise products where the vendor scopes your needs before quoting. Expect a sales cycle.

The listed price is often the starting price. Complex apps can need configuration, data migration or integration work before they are useful, so budget for implementation as well as the licence. Check too whether the app is billed through Salesforce or directly by the vendor, because it changes your procurement route and contract terms.

How to evaluate and install an AppExchange app safely

Installing a package into your org is not like downloading a phone app. A bad install can break existing automation, consume API limits or open access you did not intend. Start by writing down the must-haves, nice-to-haves and deal-breakers before opening a single listing; most disappointing installs trace back to a demo that came before the requirements.

Vetting a listing

  • Reviews. Read the pattern, not the star rating. Two hundred reviews averaging 4.3 tell you more than three averaging 5.0.
  • Release history. Check when the app was last updated. One that has not shipped in a year and a half may lag behind Salesforce’s three releases a year.
  • What it needs. Look at the objects, permissions and external services the app uses, and whether it counts against your API limits.
  • A trial. Many vendors offer a trial or test drive. Test it against your real use cases and data, not a clean demo org.

Sandbox first, permission sets always

Never install a new package straight into production. Install it in a full or partial copy sandbox and test it against your existing automation, validation rules and integrations; conflicts between packages are common, especially on shared objects like Opportunity and Case.

Grant access with permission sets rather than profiles, so access is granular and easy to withdraw, and keep a record of which permission sets went to whom. It matters at audit time and when the renewal comes round.

How to list an app on the AppExchange

For a software company, getting onto the AppExchange is a real undertaking, and knowing the phases up front saves months.

  1. Join the Salesforce Partner Program as an ISV. You get a Partner Business Org, where your listing, licences and partner tools live, and access to the Partner Console.
  2. Build a second-generation managed package. In a namespace, with a Dev Hub linked to the Partner Business Org.
  3. Pass security review. Submitted through the Partner Console.
  4. Publish the listing. Description, screenshots, pricing model, a demo and, if you want trials, a test drive.
  5. Manage licences. The License Management App in your Partner Business Org records installs and controls seats and expiry.
  6. Keep releasing. Versioned upgrades pushed to subscribers, and a new review when the app changes enough to need one.

Teams that would rather focus on the product than the packaging and review can bring in a partner for AppExchange app development. Cloudoxia is a Salesforce consulting partner rated 5.0 on the AppExchange.

Second-generation managed packages

Second-generation managed packaging (2GP) is Salesforce’s current standard. Packages are built from source with the Salesforce CLI and a Dev Hub rather than a single packaging org, so development runs in a normal CI/CD pipeline with versioning in source control and scratch orgs for testing.

“Managed” matters: subscribers cannot see or change your Apex, and you decide what is extensible through global classes and interfaces. The namespace and package structure are decisions you cannot undo later, so make them before you write much code.

The security review

The review is where most first-time publishers stall. Salesforce scans the code and tests the app and any external endpoints it calls for problems such as SOQL injection, cross-site scripting, missing CRUD and field-level security checks, and excessive permissions. Common reasons a submission comes back:

  • Credentials or API keys hard-coded in Apex
  • No CRUD or field-level security check before reading or writing data
  • Broader permissions than the app needs, such as Modify All Data
  • Callouts to endpoints that are not HTTPS

Run Salesforce Code Analyzer before submitting, fix everything it flags, and document any finding you believe is a false positive. Budget six to ten weeks from submission including remediation: scanner findings clear quickly, architectural objections do not.

Fees and revenue share for publishers

Salesforce takes a share of revenue on paid apps sold through the partner program, with different rates for different agreement types, and charges a fee for security review of paid apps. Both are set in the partner agreement and have changed over the years, so confirm the current terms in the Partner Community before building a business case rather than relying on a figure in a blog post, this one included.

Plan for the running costs too: scratch orgs and test environments, keeping up with three Salesforce releases a year, and re-submitting for review when you make significant changes.

Agents on the AppExchange

The newest listings are for Agentforce: pre-built agents for jobs like lead qualification, case routing or order status, and agent actions that let an agent call into an app. For buyers, the evaluation is the same as for any app, plus one question: what can the agent do without a person approving it, and under whose permissions. For builders, exposing an app’s functions as agent actions is becoming part of being useful on the platform. If you are new to agents, start with one well-defined process, measure it, and scale from there.

Keep an app inventory

It is not unusual for an org to have a dozen or more packages installed. Keep a list of what is installed, who uses it, what it costs and when it renews, and review it once a year. Without one, you pay for tools nobody uses and discover conflicts between packages that were never tested together.

Salesforce AppExchange FAQ

What is the Salesforce AppExchange?

Salesforce’s official marketplace for apps, components, pre-built integrations, AI agents and consulting partners that extend Salesforce. Apps listed publicly have passed Salesforce’s security review.

Are AppExchange apps free?

Some are. Others are priced per user per month, per org, or on request, and the listing shows which. Budget for implementation on larger apps as well as the licence.

Are AppExchange apps safe to install?

Listed apps have passed security review, which is a strong baseline but not a guarantee that an app suits your org. Install in a sandbox first, check the permissions it needs, and grant access with permission sets.

How long does AppExchange security review take?

Budget six to ten weeks from submission, including fixing what the review finds. Running Salesforce Code Analyzer before you submit shortens it.

What is AgentExchange?

The part of Salesforce’s marketplace for Agentforce: pre-built agents, topics and agent actions from partners, which you evaluate and install like any other listing.

Contents

Keep reading

Bring us the part that isn’t working.

A 30-minute call with an architect — not a salesperson. You’ll leave it with a straight answer about scope, sequence and cost, whether or not you hire us.