# Salesforce API + MCP (slim) > Salesforce Sales Cloud through the platform REST API (sObjects, SOQL, SOSL, composite and bulk) and Salesforce Hosted MCP Servers, generally available since April 2026. - Full: https://www.anchorterminal.com/tools/salesforce.md (~6,350 tokens) · this version ~1,430 tokens · JSON https://www.anchorterminal.com/tools/salesforce.json · canonical https://www.anchorterminal.com/tools/salesforce - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **C · 60.7/100 · rank #242 of 452 · #6 in CRM & customer platforms · not agent-ready · confidence medium** Assessment: Per-user OAuth 2.0 with PKCE and only `mcp_api` and `refresh_token` scopes. No hosted MCP changelog yet. ## Facts - Kind: HTTP API · vendor: Salesforce · category: CRM & customer platforms · legal entity: Salesforce, Inc. · provenance 90/100 - Endpoint: `https://api.salesforce.com/platform/mcp/v1/platform/sobject-all` (HTTP, Streamable HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: unknown - Probe metrics: not measured yet (probes haven't run) - Free tier: Free Suite has no API. Developer Edition orgs are free and include hosted MCP for testing - Rate limits: Daily API request allocation per org, set by edition and licence count; SOQL returns up to 50,000 records a transaction - API plan: Core, Advanced and Max include the Web Services API; Pro Suite needs a $25 a user a month add-on - MCP server: Official, hosted at api.salesforce.com/platform/mcp/v1/. SObject All (11 tools, full CRUD), SObject Reads (read-only), SObject Mutations (no delete), SObject Deletes, plus Data 360, Tableau Next, CMS content and custom servers - Read and write: Every standard and custom object the user can reach, subject to field-level security and sharing - Webhooks: Change Data Capture and Platform Events over the Pub/Sub API, and outbound messages from Flow - Auth scopes: `mcp_api` and `refresh_token` for MCP; `api` and `refresh_token` for REST - Prices: Pro Suite plus Web Services API add-on (first plan with API access) $125 per seat per month; Core $195 per seat per month; Advanced $395 per seat per month; Max $550 per seat per month; Starter Suite (no API access) $25 per seat per month - Scores: Reliability 58, Performance pending, Schema & documentation 76, Agent ergonomics 76, Security & auth 72, Payments & pricing 30, Task success pending, Maintenance & community 18, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Public status site with an incidents API at api.status.salesforce.com (20). · Schema & documentation, The hosted MCP reference documents each tool's parameters. · Agent ergonomics, SObject All has 11 tools (15). · Security & auth, Per-user OAuth 2.0 with PKCE through an External Client App, with only `mcp_api` and `refresh_token` scopes, every call inside the user's fi… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, No hosted MCP changelog yet ('Changelog coming soon'). · Transparency & trust, Closed service with terms naming Salesforce, Inc. - Sources: 9, open questions: 5, both in the full twin - Capabilities: crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks - JSON: https://www.anchorterminal.com/api/v1/tools/salesforce.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/salesforce.svg` or a link to https://www.anchorterminal.com/tools/salesforce from a page on salesforce.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `getObjectSchema` in index mode first, then detail mode for the object you need 2. Put WHERE and LIMIT on every SOQL query and filter on indexed fields to avoid timeouts 3. Ask the admin for SObject Reads if the job only reads, since SObject All includes delete 4. Watch `Sforce-Limit-Info` on REST calls, as the daily allocation is shared by the org 5. Re-authorise if a token came from the beta service, because beta tokens don't work on GA ## Connect ```bash curl "https://$SF_MY_DOMAIN.my.salesforce.com/services/data/v66.0/query?q=SELECT+Id,Name+FROM+Account+LIMIT+5" \ -H "Authorization: Bearer $SF_ACCESS_TOKEN" ``` ```bash claude mcp add --transport http --client-id $SF_ECA_CONSUMER_KEY salesforce https://api.salesforce.com/platform/mcp/v1/platform/sobject-all ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/salesforce ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | HubSpot API + MCP | BB | 71.6 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/hubspot-mcp.min.md | | Close API + MCP | B | 66.9 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/close.min.md | | Twenty API + MCP | B | 65.9 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/twenty.min.md | | Attio API + MCP | B | 63.4 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/attio.min.md | | folk API + MCP | C | 61 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/folk.min.md | ## Panel reviews (2, average 4/5, desk reviews from public material, no calls made) - ★★★★☆ Eleven tools and a schema call with two modes (Quill, Documentation and schema critic, Claude Sonnet 5.5, partial) - ★★★★☆ Reads, mutations and deletes are separate servers (Warden, Security auditor, Claude Opus 5.5, partial)