Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
120 changes: 98 additions & 22 deletions guides/salesforce/external.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@ setup_version: 1

# Connect Salesforce to the Speakeasy AI Control Plane

Use Salesforce System Administrator credentials for an API-enabled production or sandbox org where Hosted MCP Servers are available. Salesforce documents availability for Enterprise Edition and above. You need authority to create an **External Client App** and enable Hosted MCP Servers.
Use Salesforce System Administrator credentials for an API-enabled production org where Hosted MCP Servers are available. Salesforce documents availability for Enterprise Edition and above. You need authority to install the Speakeasy application or create an **External Client App**, and enable Hosted MCP Servers.

Sign in to the Salesforce org that will expose its records. Create the credentials in that same org. This guide does not cover scratch orgs.
Sign in to the Salesforce org you want to connect. Install or create the app in that same org. This guide does not cover scratch orgs. For a lower-edition org, confirm Hosted MCP availability in [Salesforce Setup](#open-salesforce-setup) before starting either path.

### Open Salesforce Setup {#open-salesforce-setup}

Expand All @@ -21,6 +21,32 @@ For a lower-edition org:

<!-- screenshot: the Salesforce page with the setup gear menu open and Setup visible -->

Choose one path: **use Speakeasy's Salesforce app** and finish OAuth with support, or **create your own Salesforce app** and connect it yourself.

## Use Speakeasy's Salesforce app

### Install Speakeasy's Salesforce application {#install-speakeasy-application}

Open this installation URL to install Speakeasy's Salesforce application into the intended org:

```
https://login.salesforce.com/packaging/installPackage.apexp?p0=04tdM000000cNGXQA2
```

<!-- screenshot-exception: no verified installation screen is available; use the exact installation link rather than a fabricated UI description -->

### Contact Speakeasy support to finish OAuth {#contact-speakeasy-support}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should mention where:


After installation, **contact Speakeasy support to finish OAuth setup**. Installation alone does not complete OAuth. Coordinate your selected endpoint and [server activation](#enable-sobject-server) with support. Your next step is with support—not the app-creation walkthrough below.

<!-- screenshot-exception: this is a support handoff, not a documented console UI -->

## Create your own Salesforce app

Before creating the app, choose a server in the [endpoint reference](#endpoint-reference) and confirm its prerequisites. Then create an **External Client App** in the org you want to connect and enable that server.

This path uses the app's **Consumer Key** without a client secret. Salesforce documents this configuration for compatible public clients; it has not been verified with the Speakeasy AI Control Plane.

### Start an External Client App {#start-external-client-app}

1. In **Quick Find**, enter `external client`.
Expand Down Expand Up @@ -59,7 +85,7 @@ For a lower-edition org:

Select **Create**.

The app can take up to 30 minutes to become operational. If attaching it immediately fails even though the settings are correct, wait for that window before changing the configuration.
The app can take up to 30 minutes to become operational. If attachment fails immediately, allow that window before retrying.

<!-- screenshot-exception: Create is a standard action with no distinct configuration state to capture -->

Expand All @@ -70,34 +96,84 @@ The app can take up to 30 minutes to become operational. If attaching it immedia
3. Complete the Salesforce verification prompt if it appears.
4. Copy **Consumer Key**. You will use it as the Speakeasy **Client ID**.

<!-- screenshot-exception: the credential is sensitive and the screen adds no setup information beyond the exact label; do not capture the key -->
Do not copy the **Consumer Secret** for this path.

### Enable the selected SObject server {#enable-sobject-server}

Choose the least-privileged server that meets the team's needs:
<!-- screenshot-exception: the credential is sensitive and the screen adds no setup information beyond the exact label; do not capture the key -->

- `sobject-reads` allows discovery, query, search, and relationship traversal without changing records.
- `sobject-mutations` allows reading, creating, and updating records without deleting them.
- `sobject-deletes` allows identifying and deleting records without creating or updating them.
- `sobject-all` allows creating, reading, updating, deleting, querying, and searching records.
### Enable the selected MCP server {#enable-sobject-server}

If the ticket does not specify the team's approved read, write, or delete requirements, obtain the server choice from the application or cloud security owner.
Choose the least-privileged server that meets your team's needs using the endpoint reference below. If you are unsure which capabilities are approved, ask the application or cloud security owner before enabling a server.

1. Return to **Setup**.
2. In **Quick Find**, enter `MCP Servers`.
3. Select **MCP Servers** under **API Catalog**.
4. Find the server whose API ID matches the approved choice.
5. Use the available control to enable that server.
6. Record its URL from the table below, using the production or sandbox form that matches the org.
5. Use the available control to enable that server. For Headless 360, find `headless-360` and select **Activate**.
6. Record its URL from the endpoint reference below.
7. Wait up to two minutes for the server to become active.

| Server | Production URL | Sandbox URL |
| --- | --- | --- |
| `sobject-reads` | `https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads` | `https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-reads` |
| `sobject-mutations` | `https://api.salesforce.com/platform/mcp/v1/platform/sobject-mutations` | `https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-mutations` |
| `sobject-deletes` | `https://api.salesforce.com/platform/mcp/v1/platform/sobject-deletes` | `https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-deletes` |
| `sobject-all` | `https://api.salesforce.com/platform/mcp/v1/platform/sobject-all` | `https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-all` |
<!-- screenshot: MCP Servers under API Catalog, showing the available server list and the control used to enable the chosen MCP server; record the rendered row and control labels -->

If you created your own app, continue to [Speakeasy setup](speakeasy.md#add-server-in-speakeasy) with your selected URL and **Consumer Key**. If you installed Speakeasy's app, continue with Speakeasy support.

## Endpoint reference

The following endpoints are for production orgs. Copy the URL for your selected server.

**SObject Reads (sobject-reads)**

Discovery, query, search, and relationship traversal; no record changes.

```
https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads
```

**SObject Mutations (sobject-mutations)**

Read, create, and update records; no deletes.

```
https://api.salesforce.com/platform/mcp/v1/platform/sobject-mutations
```

**SObject Deletes (sobject-deletes)**

Identify and delete records; no creates or updates.

```
https://api.salesforce.com/platform/mcp/v1/platform/sobject-deletes
```

**SObject All (sobject-all)**

Create, read, update, delete, query, and search records.

```
https://api.salesforce.com/platform/mcp/v1/platform/sobject-all
```

**Data 360 (data360)**

Query data and change customer-data configuration. Requires a Data 360 license, API v66.0+, and **Manage Data 360** for configuration or **View Data 360** for read-only operations.

```
https://api.salesforce.com/platform/mcp/v1/data/data360
```

**Headless 360 (Beta) (platform/headless-360)**

Broad Setup and platform operations, not read-only record access. Available starting July 2026 under Beta Services Terms. Requires API v67.0+, an External Client App with `mcp_api`, and an OAuth client.

```
https://api.salesforce.com/platform/mcp/v1/platform/headless-360
```

**Tableau Next (analytics/tableau-next)**

Semantic-model and analytics access. Confirm the org has the required Tableau Next capabilities.

If the connection fails with valid credentials, confirm that the selected server is enabled, the URL matches the server and org type, and the org has API access.
```
https://api.salesforce.com/platform/mcp/v1/analytics/tableau-next
```

<!-- screenshot: MCP Servers under API Catalog, showing the available server list and the control used to enable the chosen SObject server; record the rendered row and control labels -->
Calls remain subject to the signed-in user's field-level security, object permissions, and sharing rules. If the connection fails with valid credentials, confirm that the selected server is enabled, the URL matches the selected server, and the org has API access.
106 changes: 104 additions & 2 deletions guides/salesforce/meta.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,15 @@
schema_version: 1
slug: salesforce
title: Salesforce
summary: Connect to Salesforce records through hosted SObject MCP servers with selectable read, write, and delete boundaries.
summary: Connect to Salesforce hosted MCP servers using the Speakeasy application with a required support handoff or your own External Client App, selecting the appropriate endpoint and org type.
aliases:
- com.pulsemcp.mirror/gram-salesforce
credential_setup:
options:
- id: speakeasy-application
kind: oauth
client_registration: manual
upstream_setup: provider-steps
- id: oauth-client
kind: oauth
client_registration: manual
Expand All @@ -18,7 +22,7 @@ credential_setup:
- external.md#copy-consumer-key
requirements:
- id: salesforce-admin
description: Salesforce System Administrator access to an API-enabled org where Hosted MCP Servers are available, with authority to create an External Client App and enable servers
description: Salesforce System Administrator access to an API-enabled org where Hosted MCP Servers are available, with authority to install the Speakeasy application or create an External Client App, and enable the selected servers
documentation:
external: external.md
speakeasy: speakeasy.md
Expand All @@ -29,41 +33,85 @@ remotes:
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-reads-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-reads
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-mutations-production
url: https://api.salesforce.com/platform/mcp/v1/platform/sobject-mutations
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-mutations-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-mutations
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-deletes-production
url: https://api.salesforce.com/platform/mcp/v1/platform/sobject-deletes
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-deletes-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-deletes
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-all-production
url: https://api.salesforce.com/platform/mcp/v1/platform/sobject-all
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: sobject-all-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-all
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: data360-production
url: https://api.salesforce.com/platform/mcp/v1/data/data360
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: data360-sandbox
url: https://api.salesforce.com/platform/mcp/v1/data/sandbox/data360
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: headless-360-production
url: https://api.salesforce.com/platform/mcp/v1/platform/headless-360
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: headless-360-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/headless-360
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: tableau-next-production
url: https://api.salesforce.com/platform/mcp/v1/analytics/tableau-next
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
- id: tableau-next-sandbox
url: https://api.salesforce.com/platform/mcp/v1/sandbox/analytics/tableau-next
transport: streamable-http
authentication:
- oauth-client
- speakeasy-application
provenance:
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html
Expand Down Expand Up @@ -175,3 +223,57 @@ provenance:
name: Speakeasy setup canonical section
classification: official
observed_at: "2026-08-06T23:23:14Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/setup-overview.html
name: Set Up Your Org
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/create-external-client-app.html
name: Create an External Client App
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html
name: Salesforce Hosted MCP Servers
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/client-connection-overview.html
name: Connecting an MCP Client
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/servers-reference.html
name: Standard MCP Servers Reference
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/activate-mcp-servers.html
name: Activate MCP Servers
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/data360-mcp.html
name: Data 360 MCP Server
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/headless-360-mcp.html
name: Headless 360 MCP Server (Beta)
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/tableau-next.html
name: Tableau Next
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: provider-documentation
locator: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/postman.html
name: Configure Postman
classification: official
observed_at: "2026-09-17T16:15:46Z"
- source: operator-instruction
locator: https://login.salesforce.com/packaging/installPackage.apexp?p0=04tdM000000cNGXQA2
name: Speakeasy Salesforce application installation and mandatory support OAuth handoff
observed_at: "2026-09-17T16:15:46Z"
Loading
Loading