Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The correct setup depends on which side is the MCP client. If an Agentforce agent must call a third-party MCP server, register that server in Agentforce Registry (or use the manual external-server path in API Catalog), validate it, review its tools, and add approved tools as agent actions. If Claude, ChatGPT, Cursor, Postman, or another MCP client must call Salesforce-hosted tools, enable the hosted server in Salesforce, create an External Client App for OAuth, configure the client, and test a tool request. Salesforce DX MCP is a separate local-development option installed with the @salesforce/mcp npm package.

Choose the connection direction first

“Connect Salesforce to an MCP server” describes two opposite data flows. Decide which one you need before opening Setup:

Goal MCP client Where you configure it
Agentforce uses tools hosted by a third-party, MuleSoft, or other external MCP server Agentforce Agentforce Registry; API Catalog for the manual external-server route and Salesforce-hosted server setup
An external client uses MCP tools hosted by Salesforce Claude, ChatGPT, Cursor, Postman, or another compatible client Salesforce API Catalog plus an External Client App OAuth configuration
Local development tools use Salesforce org data Your local MCP client The client’s MCP configuration and the Salesforce DX MCP package

Licenses, editions, regions, user permissions, and feature availability can change. Confirm the target org’s eligibility before designing a rollout.

Route 1: Let Agentforce call an external MCP server

Register the server in Agentforce Registry

  1. In Salesforce Setup, use Quick Find to open Agentforce Registry and select New. Salesforce documents this route for Lightning Experience Enterprise, Performance, Unlimited, and Developer editions, but required add-on licenses vary by agent type. The registering user needs Manage AI Agents and any permissions required by that agent type.
  2. Choose a prepackaged server from AgentExchange or select the option to register one from scratch. Enter a server name, description, and its HTTPS endpoint. Use the URL supplied by the MCP vendor; do not substitute a guessed endpoint.
  3. Select the authentication method required by that server. For OAuth 2.0, Salesforce asks for the identity-provider URL, optional comma-separated scopes, client ID, and client secret. Obtain every value from the server operator or its current documentation. Treat the secret as a credential.
  4. Select Create and Continue. Salesforce creates the connection and pings the endpoint. It also creates a named credential, external credential, and permission set, and gives the registering administrator a server-specific permission set for management. Salesforce says that permission set does not need to be assigned to the agent user merely for the agent to use the tools; retain it for the administrator who manages the registration.
  5. Inspect the returned tool names and descriptions, including risk warnings. Allowlist only tools whose purpose and data scope you understand. Copy descriptions into a text editor if necessary so you can spot bidirectional or decorative Unicode, invisible characters, or mixed scripts.
  6. Apply any available Agentforce Gateway policies, save, and open the Agentforce asset library. Allowed MCP tools become agent actions. Add only the actions the agent needs. If an action is missing, refresh the Agentforce Assets page.

What Salesforce’s risk review means

External tool metadata is executable-context input, not harmless documentation. Salesforce warns that tool poisoning can place instructions in descriptions that attempt data exfiltration, privilege escalation, or guardrail bypass. A successful connection is not approval to expose every tool. Review the risk assessment, least-privilege scope, write operations, and records the tool can reach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Manual registration through API Catalog

Some organizations use the API Catalog path instead. Go to Setup → API Catalog → MCP Servers → External Servers → Add MCP Server → Register External MCP Server. Enter a unique name, description, HTTPS endpoint, and authentication details. OAuth 2.0 uses the same provider-specific identity URL, scopes, client ID, and secret fields; advanced OAuth 2.1 authentication is handled through Agentforce Registry documentation. Salesforce pings the server and displays a risk assessment. Low-risk findings require no action; medium- and high-risk findings require review and acceptance before continuing.

Management follows the registration location: third-party servers connected through Agentforce Registry are managed there, while other API Catalog MCP connections are managed in API Catalog.

Route 2: Let an external MCP client call Salesforce-hosted tools

Enable the server in Salesforce

  1. In Setup, open API Catalog → MCP Servers and enable the hosted server your team needs. Salesforce-hosted MCP servers are disabled by default and must be enabled by an administrator.
  2. Allow up to two minutes for activation. If a client still cannot connect after valid OAuth setup, check this org-level toggle before changing client settings.

Create the OAuth client

  1. Create an External Client App in the Salesforce org. Configure the OAuth settings required by the client and record the app’s consumer key.
  2. In the MCP client, enter the Salesforce MCP server URL, consumer key, and the OAuth Authorization Code flow with PKCE details requested by Salesforce and the client.
  3. Run a simple tool request and inspect the raw response. Salesforce specifically recommends Postman as a first test because it invokes tools directly and returns JSON without an LLM interpreting the result.

Salesforce states that Connected Apps cannot be used for MCP authentication in this flow. Agentforce Vibes is the exception: its Salesforce Platform MCP servers are automatically enabled and it does not require the External Client App step. Claude, ChatGPT, Cursor, Postman, and Agentforce Vibes are among the clients Salesforce documents as tested; other clients that support OAuth 2.0 Authorization Code with PKCE may also work.

Route 3: Use Salesforce DX MCP for local development

Salesforce DX MCP is the @salesforce/mcp npm package. Install Node.js Active LTS, then add the package to your MCP client’s JSON configuration using npx. The exact JSON file and field names differ by client, so follow that client’s current configuration format rather than copying an example blindly. Agentforce Vibes includes the DX server preconfigured.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limit orgs and tools deliberately

Authorize at least one Salesforce org, then specify the orgs and toolsets the server may access. Salesforce recommends not automatically exposing every authorized org. The DX server offers over 60 tools (Salesforce, Salesforce DX Developer Guide, accessed 2026), so expose only the toolsets or individual tools required for the task. Use --toolsets or --tools; the all toolset enables everything. The experimental --dynamic-tools option discovers tools at runtime and may not work in every client. The package’s @latest tag can change over time, so recheck the current DX guide before pinning a production configuration.

Authentication and permission checklist

  • Identify the client and server side before selecting a Salesforce setup page.
  • Use an HTTPS endpoint and the authentication method specified by the MCP provider.
  • Never invent OAuth scopes, identity-provider URLs, client IDs, or secrets.
  • Grant the administrator’s registration permission set to the people who manage the connection, not broadly to agents.
  • Allowlist individual tools and inspect descriptions for hidden or suspicious instructions.
  • For hosted Salesforce MCP, enable the server at the org level and use an External Client App, not a Connected App.
  • For DX MCP, restrict authorized orgs and select only necessary toolsets.

Troubleshooting common failures

The Registry or API Catalog menu is missing

Check the org edition, required Agentforce add-on license, user permissions, and whether your Salesforce release exposes that feature. A missing menu is usually an eligibility or permission issue, not an MCP URL problem.

Connection validation fails

Confirm the endpoint is HTTPS and reachable, then compare the identity-provider URL, client ID, secret, and scopes character-for-character with the MCP provider’s instructions. Rotate a secret that may have been exposed. For a hosted server, verify the org-level server toggle and wait for activation.

The server connects but no tools appear

Refresh the Agentforce Assets page, confirm that tools were allowlisted, and check the risk assessment for blocked or unaccepted findings. In a local DX setup, verify that a toolset or explicit tool list is present; exposing no toolset intentionally produces no usable tools.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An agent behaves unsafely around a tool

Remove the tool from the allowlist while investigating. Review its description for Unicode tricks, hidden instructions, unexpected write operations, and excessive data access. Re-enable only after the scope and behavior are understood.

LLM output looks wrong

Separate protocol problems from model interpretation. Call the tool from Postman or another raw MCP client and inspect the JSON response first. If the protocol response is correct, investigate the agent prompt, permissions, and action mapping rather than repeatedly changing OAuth settings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your workflow also needs reliable website captures—for example, documenting a Salesforce login or public page—ScreenshotNeo provides a one-request screenshot API and MCP server:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://salesforce.com -o shot.webp

See the ScreenshotNeo API documentation for request options. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and whether the request was billed. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can a Salesforce Developer Edition org use Salesforce-hosted MCP?

Availability depends on the specific hosted server, current Salesforce release, permissions, and licensing. Enable the server in API Catalog and verify the org’s eligibility rather than assuming every Developer Edition feature is enabled.

Can I use a Connected App for an external MCP client?

No. Salesforce’s hosted-MCP guidance requires an External Client App for this flow; Agentforce Vibes is the documented exception.

Should I expose every DX MCP tool to my coding assistant?

No. Select only required orgs and toolsets or tools. Salesforce documents over 60 DX tools, and exposing all of them increases context and access unnecessarily.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.