Now deploying Agentforce with clients in retail, staffing & care: see how AI agents fit your operation
NL / EN (current)
Book a Free Scan
Salesforce MCP

Salesforce MCP: the complete guide to the Model Context Protocol

MCP, the Model Context Protocol, is the open standard that lets AI agents use tools and data through one common interface instead of custom integrations. On Salesforce it means an agent, whether Claude, an IDE assistant or Agentforce itself, can read and act on your platform under your existing permissions. This guide explains what MCP is, what Salesforce ships today, how Claude connects, and how to govern all of it.

What is MCP?

The Model Context Protocol is an open protocol, introduced by Anthropic, that standardises how AI applications connect to tools and data sources. Before MCP, every agent-to-system connection was a bespoke integration: one-off code, one-off security review, one-off maintenance. With MCP, a system exposes its capabilities once, as an MCP server, and any MCP-compatible agent can use them.

The practical consequence for an enterprise: the question shifts from "can we wire this AI tool to that system" to "which capabilities do we expose, to which agents, under which permissions". That is an architecture and governance question, which is exactly where it belongs.

What Salesforce ships today

Salesforce has put MCP at the centre of its agent strategy, and the portfolio is broader than most overviews suggest.

Hosted MCP servers, generally available

Since April 2026, Salesforce hosts and scales MCP servers for every Enterprise Edition org and above, the same way it runs the REST APIs you already use. Standard servers expose the Agentforce 360 Platform, Tableau Next and Data 360 SQL; custom servers let admins expose selected flows, Apex actions and Named Query APIs. Nothing to provision, nothing to patch: enable a server in Setup and it is live.

Headless 360

Salesforce's own name for this API-first access layer: the portfolio spanning the Salesforce Platform, Data 360, Tableau and MuleSoft that agents reach through MCP, without a person logging into the user interface. The term is new, the idea is significant: your platform becomes something agents work on, not only something people click through.

The developer and integration routes

The Salesforce DX MCP Server serves development workflows from tools such as Claude Code. On the integration side, MuleSoft can expose existing APIs and integrations as MCP servers, so the systems your platform already connects to become agent-reachable through the same governed pattern.

Agentforce as an MCP client

Agentforce agents can connect to MCP servers themselves, with a registry and gateway model for enforcing which tools an agent may call and how often. MCP is not a rival to Agentforce; it is the connective tissue between agents and systems, on both sides.

Connecting Claude to Salesforce

This is the pairing the hosted servers were built for. Connect Claude to a Salesforce hosted MCP server and it can query records, run analyses and execute permitted actions in conversation, without anyone logging into the platform. Account reviews, pipeline analyses and case summaries stop being a matter of tabs, reports and exports, and become a question you ask.

The connection is governed, not improvised: access runs through OAuth, and every operation executes as the authenticated user. Claude sees exactly what that user may see and can do exactly what that user may do, nothing more.

For the model side of this story, why Claude is the preferred model for regulated industries on the Agentforce 360 platform, see our Agentforce guide.

Security and governance: the questions that decide the project

Three facts settle most of the security conversation.

First, your existing permission model applies automatically: CRUD, field-level security and sharing rules all hold, because every MCP transaction runs as the authenticated user rather than through an anonymous service account. There is no second security model to design or audit.

Second, access control uses OAuth with PKCE, the same standards your security team already governs elsewhere.

Third, on the model side: Anthropic is the first model provider to run fully within the Salesforce trust boundary, with Claude traffic contained inside the secured Salesforce environment. For organisations in regulated sectors, that combination, protocol governance plus model containment, is what makes agent access to production data defensible.

What remains is the genuinely strategic work: deciding which capabilities to expose. A well-designed custom server is a curated set of tools for a purpose, not a firehose. That curation, more than any protocol detail, determines whether agents are useful and safe.

MCP or Agentforce actions: which do you need?

A practical rule of thumb. If the work happens inside Salesforce channels, an agent in your service console, your customer portal, your Slack, build it in Agentforce and give it actions there. If the work happens in an outside agent that must reach Salesforce, Claude for your account teams, a development assistant, a cross-system analysis, expose the capability through an MCP server.

Most enterprises end up with both, and the architecture question becomes governance: one registry of what is exposed, to whom, under which policies. That is a design exercise we run in a single session.

Book a free Agentic Scan

In one session you will see where agents and MCP fit in your processes, and what the first step costs and returns.

Book a free Agentic Scan
Frequently asked questions
What is Salesforce MCP in one sentence?

MCP, the Model Context Protocol, is the open standard through which AI agents such as Claude or Agentforce can read and act on Salesforce under your existing permissions, via MCP servers that Salesforce now hosts natively.

Is MCP safe for enterprise data?

The protocol inherits your platform's security rather than replacing it: every transaction runs as the authenticated user, so CRUD, field-level security and sharing rules apply automatically, and access is controlled through OAuth with PKCE. The real safety work is curation: deciding which capabilities a server exposes.

What are Salesforce hosted MCP servers?

MCP servers that Salesforce runs and scales for you, generally available since April 2026 for Enterprise Edition orgs and above. Standard servers expose products such as the Agentforce 360 Platform, Tableau Next and Data 360 SQL; custom servers expose the flows, Apex actions and queries you select.

How do we connect Claude to Salesforce?

Through a hosted MCP server: enable the server, authorise Claude as an MCP client through OAuth, and Claude can query and act on your org as the authenticated user. No custom integration code, and no one logging into the platform for routine questions.

Do we need Agentforce to use MCP?

No. MCP works with any compatible agent, including Claude and development tools, entirely outside Agentforce. Agentforce adds its own MCP client and a registry for governing which tools its agents may call, so the two strengthen each other rather than compete.

What is Headless 360?

Salesforce's name for the API-first access layer that MCP opens up: the portfolio spanning the Salesforce Platform, Data 360, Tableau and MuleSoft that agents can work on directly, without going through the user interface. It is the platform reframed as something agents operate, not only something people click through.

Not sure where to start?

A free scan with a senior consultant will tell you, with no obligation.

Book a Free Scan