@mindstone/mcp-server-salesforce

Salesforce CRM MCP server โ accounts, contacts, opportunities, leads, tasks, users, and custom objects via the Salesforce API.
Best when an MCP host needs a local, install-and-run CRM connector for everyday sales work rather than a Salesforce-hosted endpoint.
Status
- Version: 0.2.2 ยท npm
- Auth: OAuth (local 127.0.0.1 callback) or static access token (
SALESFORCE_CLIENT_SECRET, SALESFORCE_ACCESS_TOKEN)
- Tools: 37 (accounts, contacts, opportunities, leads, tasks, cases, events, search, notes, campaigns, reports, query)
- Surface: cloud-api
- Machine-readable:
STATUS.json
Why this exists
Salesforce's own MCP options are the right starting point for many teams. This package is for teams that want a normal npm MCP server they can run locally in any stdio host.
It gives an assistant focused access to the CRM work people actually ask for: finding accounts and contacts, updating leads, creating opportunities and tasks, running CRM searches, and working with custom objects. The benefit is a short path from a natural-language sales request to the right Salesforce records, with write actions kept visible to the host.
Example interaction
"Find Acme Corp in Salesforce, create a Q3 expansion opportunity for $75,000, and add a follow-up task for next Friday."
Tools the host calls:
salesforce_get_accounts โ searches accounts by name and returns the matching account ID.
salesforce_create_opportunity โ creates the opportunity against that account.
salesforce_create_task โ adds a follow-up task related to the new opportunity.
Response (trimmed):
{
"account": { "id": "001xx000003DGbYAAW", "name": "Acme Corp" },
"opportunity": {
"id": "006xx000004TmiYAAS",
"name": "Q3 expansion",
"amount": 75000,
"stage": "Prospecting"
},
"task": {
"id": "00Txx000006rYxDEAU",
"subject": "Follow up on Q3 expansion"
}
}
Requirements
- Node.js 20+
- npm
- A Salesforce Connected App for the OAuth path, or a valid access token plus instance URL for manual-token mode.
One-click install

After clicking the button, your host will prompt you to fill: SALESFORCE_CLIENT_ID, SALESFORCE_CLIENT_SECRET, SALESFORCE_ACCESS_TOKEN, SALESFORCE_CONFIG_DIR, SALESFORCE_OAUTH_PORT.
Manual config for Claude Desktop / Claude Code / Goose / Continue.dev (Salesforce)
{
"mcpServers": {
"Salesforce": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-salesforce"
],
"env": {
"SALESFORCE_CLIENT_ID": "",
"SALESFORCE_CLIENT_SECRET": "",
"SALESFORCE_ACCESS_TOKEN": "",
"SALESFORCE_CONFIG_DIR": "~/.mcp/salesforce",
"SALESFORCE_OAUTH_PORT": "0"
}
}
}
}
Quick Start
Install & build
cd <path-to-repo>/connectors/salesforce
npm install
npm run build
npx
npx -y @mindstone/mcp-server-salesforce
Local
Configuration
OAuth (Recommended)
Set these environment variables:
SALESFORCE_CLIENT_ID โ Your Salesforce Connected App client ID
SALESFORCE_CLIENT_SECRET โ Your Salesforce Connected App client secret
SALESFORCE_SANDBOX โ Set to "true" for sandbox environments (optional)
Then call salesforce_connect_account to start the OAuth flow.
Manual Token
SALESFORCE_ACCESS_TOKEN โ A valid Salesforce access token
SALESFORCE_INSTANCE_URL โ Your Salesforce instance URL (e.g., https://mycompany.my.salesforce.com)
Additional Options
SALESFORCE_CONFIG_DIR โ Custom config directory (default: ~/.mcp/salesforce)
SALESFORCE_OAUTH_PORT โ OAuth callback port (0 = OS-assigned; default: 0)
SALESFORCE_OAUTH_SCOPES โ Space-separated OAuth scopes. Leave unset to use the connector default.
Account Management
salesforce_connect_account โ Connect a Salesforce account via OAuth
salesforce_list_connected_accounts โ List connected accounts
salesforce_disconnect_account โ Disconnect an account
CRM Accounts
salesforce_get_accounts โ Get CRM accounts with filters
salesforce_create_account โ Create a CRM account
salesforce_update_account โ Update a CRM account
salesforce_get_contacts โ Get contacts with filters
salesforce_create_contact โ Create a contact
salesforce_update_contact โ Update a contact
Opportunities
salesforce_get_opportunities โ Get opportunities with filters
salesforce_create_opportunity โ Create an opportunity
salesforce_update_opportunity โ Update an opportunity
Leads
salesforce_get_leads โ Get leads with filters
salesforce_create_lead โ Create a lead
salesforce_convert_lead โ Convert a lead to Account + Contact
salesforce_update_lead โ Update a lead
Tasks
salesforce_get_tasks โ Get tasks with filters
salesforce_create_task โ Create a task
salesforce_update_task โ Update a task
Cases
salesforce_get_cases โ Get support cases with filters
salesforce_create_case โ Create a support case
salesforce_update_case โ Update a support case
Events
salesforce_get_events โ Get calendar events with filters
salesforce_create_event โ Create a calendar event
Search
salesforce_search โ Cross-object full-text search (SOSL); the response's truncated flag tells you whether more matches exist beyond the limit
Notes
salesforce_get_notes โ Get notes attached to a record
salesforce_create_note โ Create a note, optionally attached to a record (a failed attach rolls the note back, or reports the orphaned note ID)
Campaigns
salesforce_get_campaigns โ Get marketing campaigns with filters
salesforce_get_campaign_members โ Get leads/contacts in a campaign
Reports
salesforce_run_report โ Run an existing Salesforce report (Analytics REST API)
Users
salesforce_get_users โ Get Salesforce users
Query & Schema
salesforce_query โ Execute raw SOQL queries
salesforce_describe_object โ Get object metadata and fields
salesforce_list_objects โ List available Salesforce objects
Generic CRUD
salesforce_create_record โ Create any Salesforce record
salesforce_update_record โ Update any Salesforce record
salesforce_get_records โ Query any Salesforce object
Security notes
- The standalone OAuth callback server binds to
127.0.0.1; it does not honour environment overrides that would expose the callback beyond loopback.
- OAuth credentials are stored under
SALESFORCE_CONFIG_DIR (default ~/.mcp/salesforce) with restrictive directory and file permissions.
- Write and disconnect tools are marked so capable hosts can ask for confirmation before changing Salesforce data.
- SOQL helper paths escape string and
LIKE values, strip comments quote-safely before applying the query limit cap, and enforce a maximum of 200 records for raw SOQL queries.
- Record text returned by read tools is wrapped in
<untrusted-content> envelopes so Salesforce-authored field values are presented to the model as data, not instructions.
salesforce_convert_lead reports a conversion as failed when Salesforce rejects it at the record level (e.g. a validation rule), instead of claiming success; the org-authored error detail is enveloped the same way.
Licence
FSL-1.1-MIT โ Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.