Salesforce API facts that shape an MCP server
| Fact | Detail | Source |
|---|---|---|
| Status | Salesforce Hosted MCP Servers became generally available on April 29, 2026, after a pilot in spring 2025 and a beta from October 2025, for every Enterprise Edition org and above. Salesforce hosts and scales the servers; an admin turns each one on in Setup under API Catalog, MCP Servers. | Salesforce Developers blog: Hosted MCP Servers are now generally available |
| Billing | Salesforce says Hosted MCP Servers are intended only for customers with Flex Credits and that server usage may be billed. To get Flex Credits, it points you to your account executive or to Salesforce Foundations. | Salesforce Developers: Hosted MCP Servers, get started |
| Standard servers | Standard servers are off by default, and their tool sets can’t be changed. For CRM records there are SObject Reads (read and query only), SObject Mutations (create and update, no delete), SObject Deletes and SObject All. Others cover Data 360, Tableau Next, Archive Connect, Backup and Recover and CMS content, with Headless 360 and CRM Analytics in beta. | Salesforce Developers: Standard MCP servers reference |
| Endpoint and read tools | Production URL: https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads; sandboxes and scratch orgs add /sandbox before /platform. SObject Reads has six tools: getObjectSchema, soqlQuery, find, getUserInfo, listRecentSobjectRecords and getRelatedRecords. | Salesforce Developers: SObject Reads server |
| Identity and permissions | Every tool call runs as the user who authorized the connection, with that user’s object permissions, field-level security and sharing rules, and is attributed to them in audit trails. Only the OAuth authorization code flow with PKCE is allowed: no service accounts, no machine-to-machine flows and no dynamic client registration. | Salesforce Developers: Hosted MCP security best practices |
| External Client App | Each AI client connects through an External Client App; Connected Apps aren’t supported. The app needs the mcp_api and refresh_token scopes and JWT-based access tokens for named users, and can take up to 30 minutes to start working. Any user in the org can sign in through it unless you require a permission set. | Salesforce Developers: Create an External Client App for MCP |
| Custom servers | Custom servers expose only the tools you choose: Apex invocable actions, @AuraEnabled methods, Apex REST, autolaunched Flows, Named Query API queries and API Catalog endpoints, plus Prompt Builder templates as MCP prompts. They follow the sharing and security model configured in the org. | Salesforce Developers blog: Developer’s guide to the Summer ’26 release |
| Query and delete limits | soqlQuery reads at most 50,000 records per transaction across all queries, and find (SOSL search) returns at most 2,000 records. Deleted records go to the Recycle Bin for up to 15 days, and there is no undelete tool. | Salesforce Developers: SObject All server |
| API usage | MCP tool calls count against the org’s daily API allocation, one or more calls per tool invocation, shown under Company Information as API Requests, Last 24 Hours. Turning a server on or off can take up to 2 minutes, and Experience Cloud site URLs aren’t supported yet. | Salesforce hosted MCP wiki (GitHub): Known limitations |
| Daily API allocation | Enterprise Edition, and Professional Edition with API access enabled, get 100,000 API calls per 24 hours plus 1,000 per Salesforce license; Unlimited and Performance add 5,000 per Salesforce license, and Developer Edition gets 15,000 in total. Production orgs allow 25 concurrent requests that run 20 seconds or longer. | Salesforce Developers: API request limits and allocations |
| Developer servers | Salesforce lists the Salesforce DX MCP Server as beta, for issuing commands to your orgs in natural language without writing code or queries. The same page lists MCP offerings for Heroku (the Heroku MCP Server) and MuleSoft (the Anypoint Connector for MCP and the MuleSoft MCP Server). | Agentforce Developer Guide: MCP solutions for developers |
| Salesforce in Claude | Salesforce in Claude, a beta plugin with 37 sales skills built by Salesforce, is available on all paid Claude plans for organizations Salesforce approves through its beta sign-up, which needs the latest Sales Cloud enterprise edition. It runs on the Salesforce MCP server, works in Claude chat and Cowork, and by default asks the user to approve each change. | Claude Help Center: Set up Salesforce in Claude for your organization |
Every way to connect Salesforce to AI
| Option | Type | Fits when | Limits |
|---|---|---|---|
| Salesforce Hosted MCP Servers (standard servers) | Official | Business users who want to ask CRM questions or update records from Claude, ChatGPT, Cursor or Copilot Studio under their own Salesforce permissions, with nothing to host. | Enterprise Edition and above; intended for Flex Credits customers; every call needs a signed-in user; fixed tool sets, so the model writes its own SOQL; calls count against the daily API allocation. |
| Custom server on Salesforce’s hosted MCP | Custom | Rules that belong inside Salesforce: a Named Query that returns one slice of data, a Flow that allows only certain stage changes, or an Apex action that creates a quote after your pricing checks, all under the user’s permissions. | You build and maintain the Flows, Apex and queries in the org, and the same edition, Flex Credits and signed-in-user rules apply as for the standard servers. |
| Salesforce DX MCP Server | Official | Developers and admins in VS Code, Cursor, Claude Code or Agentforce Vibes who deploy and retrieve metadata, run SOQL and Apex tests, build Lightning web components or work DevOps Center items. | Beta. Runs locally with npx against orgs authorized in the Salesforce CLI and allowlisted with --orgs; not meant for business users in chat clients. Its more than 60 tools are grouped into toolsets, and tools that aren’t GA stay off unless you pass --allow-non-ga-tools. |
| Composio or Zapier MCP | Hosted | Teams already on one of these platforms that want Salesforce actions next to other apps. Composio lists 179 Salesforce tools and 7 triggers (September 2026); Zapier offers named actions such as creating contacts or adding leads to campaigns. | They use their own Salesforce connection and tool definitions, not Salesforce’s hosted servers. Zapier bills each tool call as two tasks and doesn’t apply Enterprise-account app and action restrictions out of the box. |
| tsmztech/mcp-server-salesforce | Community | Developers testing against a sandbox who want schema, SOQL, DML and Apex tools in a local server. MIT-licensed and maintained, with release v0.0.8 in September 2026. | Unofficial. Runs locally over stdio as one Salesforce identity (username, password and security token, client credentials, the Salesforce CLI or an access token), and its tools can change objects, fields and Apex or run anonymous Apex, so keep it away from production. |
| External custom MCP server | Custom | Tools that join Salesforce with an ERP, billing or support system in one answer, quote-to-order handoffs with your own approval rules, and scheduled agents that run with no user signed in. | You host and secure it. It calls the REST API, which needs API access (on by default in Enterprise, Unlimited, Performance and Developer Edition; an add-on for Professional), and every call counts against the daily allocation. |
Tools a Salesforce MCP server should expose
Start with read-only tools and add write actions once the team trusts the answers. Every write action below runs with a confirmation or approval step.
| Tool | Access | Risk | Purpose | Guard |
|---|---|---|---|---|
get_account_360 | Read | Medium | Account owner, open opportunities, open cases and the ERP balance, overdue amount and credit status in one answer. | Salesforce data comes through the user’s own token, so field-level security and sharing apply; ERP figures only for accounts the user can see, matched by the ERP customer number in an external ID field. |
summarize_pipeline | Read | Low | Open pipeline by stage, owner and close month, with deals whose close date slipped. | Read-only aggregate queries under the user’s sharing; fixed query templates, no free-form SOQL; row cap. |
find_account_cases | Read | Low | Open cases for an account with priority, status, age and last update. | Read-only; the user’s sharing decides which cases appear; results paged. |
get_order_status | Read | Low | ERP order, delivery and invoice status for a won opportunity or a Salesforce order. | Read-only; finds the ERP order by the Salesforce record ID stored on it, only for records the user can see. |
create_follow_up_task | Write | Low | Create a task on an account, contact or opportunity with a due date and owner. | Shows the task first and creates it only after the user confirms; runs as the user. |
update_opportunity_stage | Write | Medium | Move an opportunity to a new stage, close date or next step. | Confirmation with before-and-after values; only allowed stage moves; Salesforce validation rules and field-level security still apply. |
create_quote_from_opportunity | Write | Medium | Build a quote from the opportunity’s products, with prices from the price book or the ERP. | Previews lines and totals and saves only after the user approves; discounts above your threshold go to Salesforce’s approval process. |
hand_off_order_to_erp | Write | High | Send a won opportunity or accepted quote to the ERP as a sales order and write the order number back. | Explicit approval; checks credit status and looks for an ERP order with the same Salesforce ID first, so a retry can’t create a duplicate; logged with user and document numbers. |
Connect it to Claude, ChatGPT or Copilot Studio
Claude
Salesforce tests Claude. Add a custom connector with a server URL such as https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads, choose “Use your own OAuth client” and paste the External Client App’s consumer key; the app’s callback URL is https://claude.ai/api/mcp/auth_callback. On Team and Enterprise plans an Owner adds custom connectors, and Salesforce notes Claude Code inherits the connection. Since September 15, 2026, Anthropic also offers Salesforce in Claude (beta): after Salesforce approves the org through AgentExchange, a Claude Owner enters the app’s consumer key and secret under Organization settings, Connectors, Salesforce (Beta).
ChatGPT
Salesforce tests ChatGPT through developer mode. Add the server URL (Salesforce’s steps use Settings, Apps, Create App), set the registration method to a user-defined OAuth client, paste the External Client App’s consumer key and secret (ChatGPT marks the secret optional, but Salesforce requires it), uncheck OIDC, and add ChatGPT’s callback URL to the app. In a chat, pick Salesforce under the + button. On Enterprise and Edu, an admin must grant developer-mode access. Separately, Salesforce opened a beta of its Agentforce Sales app in the ChatGPT app directory in December 2025 for Agentforce for Sales add-on and Agentforce 1 Edition customers.
Microsoft Copilot Studio
Not on Salesforce’s tested-client list, but Salesforce’s hosted MCP wiki documents it: add an existing MCP server with OAuth 2.0 (Manual), the External Client App’s consumer key and secret, the login.salesforce.com authorize and token URLs (test.salesforce.com for sandboxes, or your My Domain) and the scopes mcp_api refresh_token. Add https://teams.microsoft.com/api/platform/v1.0/oAuthRedirect and Copilot Studio’s callback URL to the app. You need a Copilot Studio license and generative orchestration. Microsoft’s Premium Salesforce connector is another route, with fixed actions such as Execute a SOQL query.
Claude implementation · Copilot implementation · ChatGPT implementation
Permissions, identity and audit
- Hosted servers run every call as the signed-in user: object permissions, field-level security and sharing rules apply, an agent can’t edit a field the user can’t edit, and changes show the user’s name in the audit trail. Filter API logs for API_CLIENT_CATEGORY = SALESFORCE_HOSTED_MCP to see MCP traffic.
- Start with SObject Reads. Add SObject Mutations (create and update, no delete) for teams that need writes, and keep SObject All and SObject Deletes for narrow, reviewed cases. Standard tool sets can’t be trimmed, so use a custom server for a shorter tool list.
- Require a permission set on each External Client App so only approved users can sign in, use one app per AI client as Salesforce recommends, set refresh tokens to 30 days or less with rotation, and turn on single logout so ending a Salesforce session ends the MCP session.
- For data an agent should see only in a fixed shape, use Named Queries or Flow and Apex tools. They can enforce rules the permission model can’t, such as allowing a case status change only to certain values.
- No language model runs on Salesforce’s side of a hosted MCP call; the model is in your AI client. Review that provider’s data terms for what Salesforce returns, and hide sensitive fields with field-level security.
- An external custom server should use each person’s own OAuth sign-in for interactive tools, and a dedicated API-only integration user with a least-privilege permission set for scheduled jobs, never a person’s credentials.
Hosting and network
- Salesforce hosts the official servers at api.salesforce.com, so there is nothing to deploy. A server change in API Catalog takes up to 2 minutes, and a new External Client App up to 30 minutes.
- Test in a sandbox first with the /sandbox URLs. Scratch orgs can’t create External Client Apps in Setup, so package the app from a Dev Hub org and install it.
- Salesforce warns that some AI clients call from IP ranges larger than its allowlist capacity, so check with the client vendor before restricting the app by IP. The mcp-remote bridge isn’t supported; use clients with native remote MCP and OAuth.
- An external custom server runs in your cloud and calls the Salesforce REST API and your ERP. Budget for API limits: every call counts against the daily allocation, and production orgs allow 25 concurrent requests that run 20 seconds or longer.
Cost and timeline
- The official servers need no infrastructure. Salesforce says they’re intended for Flex Credits customers and usage may be billed, so confirm rates with your account executive. Salesforce puts setup at under 30 minutes; the real work is choosing servers and permission sets and testing.
- A focused read-only custom server typically takes two to four weeks including security and evaluation.
- Cross-system tools with writes, such as a quote-to-order handoff to an ERP, and approval workflows take longer and are scoped after a short discovery. Zapier’s route bills each tool call as two tasks, per Zapier.
Salesforce MCP questions
Does Salesforce have an MCP server?
Yes. Salesforce Hosted MCP Servers have been generally available since April 29, 2026 for Enterprise Edition and above, with standard servers for records (SObject Reads, Mutations, Deletes and All), Data 360 and Tableau Next, and custom servers built from Flows, Apex and Named Queries. Developers also have the Salesforce DX MCP Server, which Salesforce lists as beta. A search of the official MCP Registry returns only third-party Salesforce servers.
Salesforce hosted MCP or the DX MCP server?
They do different jobs. The hosted servers run in Salesforce’s cloud and give business users governed access to records from Claude, ChatGPT or Copilot Studio. The DX MCP Server runs on a developer’s machine against orgs authorized in the Salesforce CLI, for metadata deploys, Apex tests, Lightning web components and DevOps Center work. Many teams use both.
Does it respect field-level security and sharing rules?
Yes. Every hosted tool call runs as the user who signed in, so object permissions, field-level security and sharing rules apply as they do in Lightning. The agent can never see more than that user; to give it less, use SObject Reads, Named Queries or a custom server.
Can Claude update Salesforce records?
Yes, if an admin turns on SObject Mutations or SObject All; SObject Reads has no write tools. In Claude you can adjust each tool’s permission, and Salesforce in Claude asks the user to approve each change by default. Validation rules still apply, and deleted records sit in the Recycle Bin for up to 15 days.
Does it work with ChatGPT and Copilot?
ChatGPT, yes: Salesforce tests it through developer mode with your own OAuth client. For Microsoft, Salesforce’s wiki documents the Copilot Studio setup, though Copilot Studio isn’t on its tested list, and notes that Microsoft 365 Copilot agents can connect through developer-built agent connectors. The consumer Copilot app can’t connect to external MCP servers.
Which Salesforce editions include API access and MCP?
API access is on by default in Enterprise, Unlimited, Performance and Developer Edition, and Professional Edition can add it. The hosted MCP servers need Enterprise Edition or above, and Salesforce’s wiki says Developer Edition works too. A Professional Edition org, even with the API add-on, needs a custom or third-party server over the REST API.
Does the hosted MCP server cost extra?
Salesforce says it is intended for customers with Flex Credits and usage may be billed. Tool calls also count against your daily API allocation. Your AI client may need a paid plan, and Copilot Studio needs its own license.
Official or custom?
Start official. For CRM questions and record updates by signed-in users, the hosted servers are usually enough, and AIONDATA, an independent consultancy that is not a Salesforce partner, will tell you so. Custom pays off when a tool must join Salesforce with an ERP or another system in one answer, when an agent runs on a schedule with no user signed in, which the hosted servers don’t support, or when your org isn’t eligible. We build those read-only first, with writes behind approval.