Suggest a server AI tools directory →

Salesforce MCP server

Last verified: 2026-09

SOQL and sObjects.

Community Chat, mail & docs Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code

What it does

Salesforce REST/SOQL through a session token and instance URL. Community listing — verify the package before you put a production token in it.

It sits in Chat, mail & docs: These servers act as the bot or the integration you install.

Good for

  • SOQL with LIMIT 5 on a sandbox object that is not Account.
  • Get an sObject you already have the id for.
  • Create a record only in a scratch org.
  • Do not connect a prod org-wide admin user.

Tools

  • SOQL / query — Read objects.
  • sObject get / create / update — Writes when the token can.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "salesforce": {
      "command": "npx",
      "args": [
        "-y",
        "salesforce-mcp"
      ],
      "env": {
        "SALESFORCE_ACCESS_TOKEN": "...",
        "SALESFORCE_INSTANCE_URL": "https://yourorg.my.salesforce.com"
      }
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y salesforce-mcp

Secrets it wants: SALESFORCE_ACCESS_TOKEN, SALESFORCE_INSTANCE_URL

Source repo →

How to get started

  1. Use a sandbox connected app or a least-privilege integration user.
  2. Set SALESFORCE_INSTANCE_URL and an access token that expires.
  3. Run one SOQL with LIMIT 5 on a non-sensitive object.

Access risk

CRM of record. Update/delete on Account/Opportunity is a bad first tool.

When to skip it

Skip it for HubSpot or a spreadsheet. Do not connect prod org-wide admin.

Instead: HubSpot, Airtable, PostgreSQL.

Vs alternatives

ServerOfficial?Needs a secret?Best for
SalesforceNoYesSOQL and sObjects.
HubSpotNoYesContacts and deals in HubSpot.
AirtableNoYesRead and write Airtable bases.
PostgreSQLYesYesRun SQL against a Postgres database.

More in Chat, mail & docs

All 18 in this category →

FAQ

Is the listed repo alive?

Community listing. Verify the package before SALESFORCE_ACCESS_TOKEN goes in env.

Instance URL?

https://yourorg.my.salesforce.com plus a token that expires. Integration user, least privilege.

Salesforce or HubSpot?

CRM of record wins. Update on Opportunity in prod is a bad first tool.

SOQL injection?

The model writes the query. A confused prompt can dump tables. LIMIT and a narrow user.