Salesforce's hosted MCP server lets Claude read and change your org as the signed-in user. It has been generally available since 29-04-2026. Start with the read-only server and test every write in a sandbox.
Clientell AI, the AI Salesforce admin, gives Claude a map of your org and safe writes: read-only first, a plan that names what a change would break, your approval, and rollback. Clientell MCP runs next to Salesforce's server in Claude, Cursor and VS Code.
What does the Salesforce hosted MCP server give Claude?
It gives Claude a set of tools that act on your org. Salesforce runs the server, handles sign-in and applies your existing permissions. Every call runs as the user who signed in, so field-level security, object access and sharing rules still apply (Salesforce Developers, best practices).
The standard servers are inactive by default. You turn on only the ones you want. Four of them work on records:
| Server | What Claude can do | Use it when |
|---|---|---|
sobject-reads | Read records and run queries. No writes. | You want answers, reports and audits. |
sobject-mutations | Create and update records. No delete. | You test writes in a sandbox. |
sobject-deletes | Delete records only. | Almost never. |
sobject-all | Read, create, update and delete. | A sandbox you can throw away. |
Salesforce lists these four in its best-practices guide. The SalesforceTrails setup guide (07-06-2026) counts seven servers in all, including salesforce-api-context, metadata-experts and data-cloud-queries.
Which editions get it, and does it cost anything?
Every Enterprise Edition org and above gets it. Salesforce announced general availability on 29-04-2026 (Salesforce Developers Blog).
Our comparison with Salesforce's hosted MCP lists it as bundled into Enterprise Edition and above, with usage counted against your existing API limits. Billing may change. On 22-09-2026 Salesforce Ben reported that successful MCP and API calls from registered agents will use Flex Credits, with no published rate yet. Check Salesforce's current terms before you plan around cost.
How do I connect Claude to Salesforce?
Setup has three parts: turn a server on in Setup, create an External Client App (the OAuth app that lets Claude sign in), and add the server to Claude as a custom connector or with claude mcp add. Salesforce keeps the exact screens, callback URLs and scopes current in its step-by-step walkthrough (26-05-2026), so follow that page and not a copy of it.
Three choices matter more than the clicks:
- Activate
sobject-readsfirst. Leave every write server off. - Create the app in a sandbox first, and connect Claude to the sandbox server URL before production.
- Sign in as a user with the least access that does the job.
If a server does not appear, remember that standard servers are inactive by default. Salesforce's best-practices guide covers the rest.
Want the org map in the same client? Clientell MCP installs in Claude Code with one command. See the install steps.
What can Claude read and change, and what does it not know about my org?
Claude can do what you can do, through the server you picked. Salesforce runs each call as the signed-in user. When Claude updates a record, your name sits in the audit trail (Salesforce Developers Blog, 29-04-2026).
What the server does not carry is your team's history. It returns records and metadata. It does not say why a flow exists, who asked for it, or what broke the last time someone changed it. Claude starts each session from the data, not from the decisions behind it.
For example, ask Claude why Opportunity.StageName flips after a save. It can read the flows. It cannot tell you which one your team meant to keep.
Clientell MCP covers that gap. Its Context Graph indexes objects, fields, flows, Apex, validation rules and permission sets with their dependencies. You describe a change in plain words, Claude plans it against your real org, and the plan names what the change would break. You run what you approve.
How do I stop Claude from writing to production by accident?
Salesforce's guide says access control works at three layers. Each one has its own job, and you should not make up for a gap in one layer with another.
| Layer | What it controls | What to set |
|---|---|---|
| Client (Claude) | Who connects to which server, and in some clients each tool | Set each tool to ask first |
| Server | Which tools exist | Connect sobject-reads to production |
| Platform | Field-level security, object permissions, sharing | Sign in as a user with the least access that does the job |
A safe default has five rules:
- Connect only
sobject-readsto production. - Connect
sobject-mutationsto a sandbox only, using the sandbox server URL. - Sign in as a user with the least access that works, not as a System Administrator.
- Read the change before you approve it. Salesforce marks read tools
readOnlyHintand delete toolsdestructiveHint, and clients that respect these hints ask before a destructive call. - Keep a way back. Export the records before a bulk change, and test the rollback in the sandbox first.
Clientell MCP builds that routine into the tool: a read-only scan first, a sandbox first, a plan of every change, your approval, and rollback. Read more on security and privacy.
Try it in Clientell: "Using the Clientell MCP, list every flow that writes to Opportunity.Amount in read-only mode, and explain in plain words what each one does."
Do I need anything on top of the free server, and when?
Not to read records or run queries as yourself. Salesforce's server does that well. Add a layer when one of these is true:
- Several people use Claude on the same org, and you want one shared memory of how it works.
- Writes need a reviewer, not just a confirmation click.
- Metering changes. If calls start costing credits, every read that did not need to happen costs money, and a tool that remembers your org asks less often.
Clientell MCP costs $249 a month for 1 org and 10 people, plus $25 a month for each extra person. Start the 14-day trial, no card needed. Prefer to talk first? Book a demo. See pricing for Clientell Platform at $500 a month and for extra orgs, or read how it compares in Clientell vs Claude Code and what Claude Code can and cannot do for Salesforce.
FAQ: common questions about Salesforce's MCP server
Is Salesforce's MCP server free?
Our comparison page lists it as included with Enterprise Edition and above. Salesforce Ben reported on 22-09-2026 that Flex Credits will apply to successful agent calls, with no published rate (Salesforce Ben). Check Salesforce's current terms.
Does it work with Claude Code and Claude Desktop?
Yes. Salesforce documents both. Claude Desktop connects through a custom connector, and Claude Code connects with claude mcp add. Follow Salesforce's walkthrough for the exact values.
Can Claude delete records?
Only if you connect sobject-deletes or sobject-all, and only records your signed-in user can delete. Use sobject-reads in production.
Does it work in a sandbox?
Yes. Salesforce documents a sandbox server URL. Keep write servers there.
Does Clientell MCP replace Salesforce's server?
No. It runs next to it. Salesforce's server gives Claude the data. Clientell AI gives Claude the org map and the safe-write steps.
Last updated: October 6, 2026