October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Agentforce

How to Connect Salesforce to an MCP Server (Agentforce, Hosted MCP, and DX)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First choose the connection direction. If an Agentforce agent must use a third-party MCP server, register that server in Salesforce Agentforce Registry (or API Catalog), validate it, review and allowlist its tools, and add those actions to the agent. If an external client such as Claude, ChatGPT, Cursor, or Postman must call Salesforce-hosted MCP tools, enable the server in the org, create an External Client App for OAuth, configure the client, and test a tool request. Salesforce DX MCP is a separate local-development setup using the @salesforce/mcp package.

The menus, licenses, OAuth fields, client support, and tool catalog can change. Confirm the target org’s edition, add-on licenses, permissions, region, and current Salesforce documentation before deploying.

Pick the route that matches your architecture

Goal MCP server Where you configure it What the client does
Agentforce uses an outside MCP service Third-party or MuleSoft Agentforce Registry; API Catalog is also available for manual external registration Salesforce connects outward and exposes approved tools as agent actions
Agentforce uses a Salesforce-hosted server Standard or custom Salesforce server API Catalog first, then Agentforce Registry Enable, activate, register, and allowlist tools
Claude, ChatGPT, Cursor, Postman, or another client uses Salesforce tools Salesforce-hosted MCP API Catalog and an External Client App The external client authenticates with Salesforce OAuth
Local development tools use Salesforce Salesforce DX MCP Your MCP client’s configuration and the @salesforce/mcp package The local server uses selected authorized orgs and toolsets

Connect a third-party MCP server to an Agentforce agent

1. Check edition, license, and permissions

In Lightning Experience, open Setup and use Quick Find to open Agentforce Registry. Salesforce documents this route for Enterprise, Performance, Unlimited, and Developer editions, but required add-on licenses vary by agent type. The registering user needs Manage AI Agents and the permissions required by the particular agent.

2. Register the server

  1. In Setup → Agentforce Registry, select New.
  2. Choose a server from AgentExchange or register one from scratch.
  3. Enter a unique name, description, and the server’s HTTPS URL.
  4. Select the authentication method required by that server.

For OAuth 2.0, the form can ask for an identity-provider URL, optional comma-separated scopes, client ID, and client secret. These values belong to the MCP vendor or identity provider; Salesforce does not provide universal defaults. Keep the secret in your credential-management process and never paste it into source control.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Validate the connection

Select Create and Continue. Salesforce creates the connection and pings the endpoint. It also creates a named credential, external credential, and permission set, and gives the registering administrator a server-specific permission set for management. Salesforce’s guidance says that this management permission set does not need to be assigned to the agent user for the agent to use the tools; retain it for the administrator who maintains the registration.

4. Inspect and allowlist tools

Review every tool name, description, parameter, and warning. Salesforce scans external servers for risks, including tool-poisoning patterns that can attempt data exfiltration, privilege escalation, or guardrail bypass. Copy descriptions into a text editor if necessary so you can inspect warnings about bidirectional or decorative Unicode, invisible characters, and mixed scripts or languages. Allow only tools whose purpose and data scope you understand.

5. Add approved actions to the agent

Apply any available Agentforce Gateway policies, save the registration, and add the resulting actions from the Agentforce asset library to the intended agent. If an action is missing, refresh the Agentforce Assets page. Test with a low-risk request and verify both the tool input and returned data.

Register an external server through API Catalog

Use this route when your organization manages the connection in API Catalog or when the server is not being managed as a third-party Registry entry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open Setup → API Catalog → MCP Servers → External Servers.
  2. Select Add MCP Server → Register External MCP Server.
  3. Enter a unique name, description, and HTTPS endpoint.
  4. Choose authentication. For OAuth 2.0, enter the provider’s identity-provider URL, optional scopes, client ID, and client secret.
  5. Let Salesforce create and ping the connection.
  6. Read the server risk assessment. Low risk requires no action; medium and high findings require review and acceptance.
  7. Allowlist only the tools needed by the consuming agent.

Salesforce routes advanced OAuth 2.1 authentication to Agentforce Registry guidance. Management ownership matters: third-party servers connected through Registry are managed there; other MCP servers and APIs connected in API Catalog are managed in API Catalog.

Connect Agentforce to a Salesforce-hosted MCP server

  1. In Setup → API Catalog → MCP Servers, create or select the hosted server.
  2. Add its tools and activate it in API Catalog.
  3. Register the activated server in Agentforce Registry.
  4. Review the tool metadata and allowlist the actions for the Agentforce agent.

Do not skip activation: Salesforce-hosted MCP servers are disabled in an org by default, and an administrator must enable the specific servers the team needs. Activation can take up to two minutes.

Let an external MCP client call Salesforce

Create the OAuth application

Create an External Client App in the Salesforce org, then configure the client with the Salesforce MCP server URL and the app’s consumer key. Salesforce explicitly says Connected Apps cannot be used for this MCP authentication flow. The exception is Agentforce Vibes, where the DX server is already configured and the External Client App requirement does not apply.

Enable and test the server

  1. Enable the required hosted server under Setup → API Catalog → MCP Servers.
  2. Wait for activation to propagate, potentially up to two minutes.
  3. Enter the server URL and OAuth details in the MCP client.
  4. Use Postman for a first protocol-level test when possible. It returns raw JSON, making authentication, transport, and tool-response problems easier to separate from LLM behavior.
  5. After a successful tool call, configure the production client and restrict it to the tools and data it needs.

Salesforce documents tested setup paths for Claude, ChatGPT, Cursor, Postman, and Agentforce Vibes. Other clients that support OAuth 2.0 Authorization Code with PKCE may also work, but follow the client’s current setup instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure Salesforce DX MCP for local development

Salesforce DX MCP is the @salesforce/mcp npm package, not the same service as a hosted Salesforce MCP server. Install Node.js Active LTS and configure your MCP client to launch the package with npx. The exact JSON shape differs by client, so use that client’s current configuration format rather than copying an example blindly.

Authorize at least one Salesforce org and explicitly select the orgs the server may access. Salesforce recommends not automatically specifying every authorized org. Select only the required toolsets or tools: the DX server exposes over 60 tools (Salesforce, accessed 2026), and exposing all of them can overwhelm model context. Use --toolsets or --tools; --dynamic-tools is experimental and may not work in every client. The all toolset enables every available tool and should be treated as an intentional exception. The @latest tag can change the installed version, so recheck the current DX guide when upgrading.

Security checklist before production

  • Write down which side is the MCP client and which side hosts the server.
  • Use only the OAuth endpoints, scopes, and credentials supplied by the server provider.
  • Review tool descriptions as untrusted security input; reject unexplained instructions or suspicious Unicode.
  • Allowlist the smallest useful set of tools and apply gateway policies where available.
  • Limit DX access to named orgs and required toolsets.
  • Test destructive operations in a sandbox or Developer Edition before production.
  • Log tool calls, inputs, outputs, and Salesforce user identity according to your security policy.

Troubleshooting common failures

The server cannot be reached

Confirm the endpoint is HTTPS, publicly reachable from Salesforce, and free of a typo or redirect that the service does not support. Re-run the Registry or API Catalog validation after correcting DNS, firewall, or TLS issues.

OAuth validation fails

Recheck the identity-provider URL, client ID, secret, scopes, redirect requirements, and whether the provider expects OAuth 2.0 or 2.1. Do not guess values. For a hosted Salesforce server, verify that the client uses an External Client App rather than a Connected App.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The server is enabled but the client still fails

Verify the administrator enabled that specific server in API Catalog and allow up to two minutes for activation. Then test with Postman to isolate protocol authentication from client-specific behavior.

A tool is missing from Agentforce

Confirm it was allowlisted, the server is active, and the action was added to the agent. Refresh the Agentforce Assets page if Salesforce created the action but the UI has not displayed it.

The DX server overwhelms the model

Replace an all toolset with named toolsets or individual tools, and remove unused authorized orgs. Avoid experimental dynamic discovery unless the client supports it reliably.

Risk warnings appear in tool metadata

Pause the rollout. Inspect the exact description and assessment, ask the vendor to explain unexpected instructions, and allow the tool only after a human owner accepts the data and privilege implications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For website screenshots used in Salesforce documentation, dashboards, or agent workflows, ScreenshotNeo provides a one-call API and an MCP server. It accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status.

See the ScreenshotNeo documentation for options such as full-page capture, CSS selectors, device presets, PDF output, custom headers and cookies, waits, blocking, caching, signed links, asynchronous jobs, bulk capture, and MCP tools for AI clients.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

An MCP server lets Claude, Cursor, or another MCP client take screenshots. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can a Salesforce Developer Edition org use MCP?

The documented routes include Developer edition for Agentforce Registry, but licenses, permissions, hosted-server availability, and specific tool access still must be verified in the target org.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I use Agentforce Registry or API Catalog?

Use Agentforce Registry for a third-party server consumed by Agentforce. Use API Catalog for manual external registration and for activating Salesforce-hosted servers; the resulting hosted server can then be registered in Agentforce Registry.

Can I use a Connected App for an external client calling Salesforce MCP?

No. Salesforce specifies an External Client App for this flow, with Agentforce Vibes as the stated exception.

The Bottom Line

Make the client-server direction explicit, register the connection in the matching Salesforce surface, validate credentials, and treat every MCP tool description as security-sensitive input. Start with a narrowly allowlisted tool set and a protocol-level test before expanding access.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.