Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Salesforce CLI MCP Server

Monorepo with two packages, both built on top of the local sf CLI:

  • packages/sf-core — shared engine that shells out to sf. No state, no auth handling of its own — sf already owns org authorization locally (sf org login web). Includes the Production write-block guard (see below).
  • packages/mcp-server — MCP server (stdio transport) exposing read-only tools: list_orgs, get_org_info, run_soql, describe_sobject, list_metadata, get_field_dependencies, find_field_in_reports.

Production safety

Production orgs can be connected and read from, but writes/deploys to Production are structurally blocked, not just discouraged. sf-core classifies every target org via SELECT IsSandbox FROM Organization (the authoritative source, not CLI alias metadata) and gates any raw/write-capable command with a default-deny allowlist of read-only sf subcommands when the org is Production. This guard lives in sf-core, so every caller — current and future MCP tools alike — inherits it automatically. See packages/sf-core/src/rawCommand.ts and classify.ts.

Prerequisites

  • Node.js 18+ and npm
  • Salesforce CLI (sf) installed and at least one org authorized: sf org login web --alias my-org

Setup

npm install
npm run build

Running the MCP server

node packages/mcp-server/dist/index.js

Point your MCP client (e.g. Claude Desktop's claude_desktop_config.json) at this command with an absolute path, or publish the package and run it via npx. Example claude_desktop_config.json entry:

{
  "mcpServers": {
    "salesforce": {
      "command": "node",
      "args": ["/absolute/path/to/salesforce-mcp/packages/mcp-server/dist/index.js"]
    }
  }
}

About

Yet another Salesforce MCP server. This requires the Salesforce CLI installed.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages