Salesforce MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SALESFORCE_DOMAIN | No | Salesforce domain: 'login' for production or 'test' for sandbox (default is 'login') | login |
| SALESFORCE_PASSWORD | No | Your Salesforce password (required for username/password authentication) | |
| SALESFORCE_USERNAME | No | Your Salesforce username (required for username/password authentication) | |
| SALESFORCE_ACCESS_MODE | No | Control which tools are available: 'read' (safe exploration), 'read_write' (CRM operations), or 'all' (full API access, default) | all |
| SALESFORCE_ACCESS_TOKEN | No | Your Salesforce OAuth access token (required for OAuth authentication) | |
| SALESFORCE_INSTANCE_URL | No | The Salesforce instance URL (required for OAuth authentication) | |
| SALESFORCE_SECURITY_TOKEN | No | Your Salesforce security token (required for username/password authentication) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_objectsA | List all Salesforce objects in this org. Use this as the first step when exploring an unfamiliar org or when you need to find a custom object. |
| describe_objectA | Get complete metadata for a Salesforce object: fields, relationships, picklist values, and record types. Call this before querying or writing to an unfamiliar object. |
| run_soql_queryA | Execute a SOQL query. SOQL syntax: SELECT fields FROM Object WHERE conditions ORDER BY field LIMIT n |
| run_sosl_searchA | Search across multiple Salesforce objects by keyword using full-text search. |
| get_recordA | Get a single Salesforce record by its ID. Returns all readable fields. |
| create_recordA | Create a new Salesforce record. Provide the object name and a dict of field values. |
| update_recordA | Update fields on an existing Salesforce record. Only include fields you want to change. |
| delete_recordA | Permanently delete a Salesforce record. This cannot be undone via the API. Records go to the Recycle Bin and can be recovered by an admin within 15 days. |
| tooling_executeA | Execute a Salesforce Tooling API call. The Tooling API accesses metadata and developer objects: ApexClass, ApexTrigger, CustomField, Flow, ValidationRule. |
| apex_executeB | Call a custom Apex REST endpoint. These are org-specific REST services written in Apex by developers. The action is the URL path after /services/apexrest/. This will return an error if no custom Apex REST endpoints exist in the org. |
| restfulA | Execute a raw Salesforce REST API call. This is an escape hatch for API endpoints not covered by other tools. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 11 tools
Each tool has a distinct purpose with clear boundaries. For example, create_record, get_record, update_record, and delete_record form a clean CRUD pattern, while run_soql_query and run_sosl_search differentiate between structured queries and full-text searches. The apex_execute, restful, and tooling_execute tools serve as specialized escape hatches for custom Apex, raw REST API, and metadata operations, respectively, with no overlap in functionality.
All tool names follow a consistent verb_noun pattern using snake_case, such as create_record, describe_object, and run_soql_query. This uniformity makes the tool set predictable and easy to navigate, with no deviations in naming conventions across the 11 tools.
With 11 tools, the server is well-scoped for Salesforce operations, covering core data management (CRUD), metadata exploration, querying, and specialized API calls. Each tool serves a specific role without redundancy, making the count appropriate for the domain's complexity and typical use cases.
The tool set provides comprehensive coverage for Salesforce interactions, including full CRUD lifecycle for records, metadata inspection with list_objects and describe_object, querying via SOQL and SOSL, and escape hatches for custom and raw API calls. There are no obvious gaps; agents can perform all essential operations from exploration to data manipulation and integration.