The short version
Yes, Salesforce has its own MCP server. Salesforce Hosted MCP Servers have been generally available since April 2026. They run at api.salesforce.com/platform/mcp/v1/, sign each user in with OAuth, and work in Claude, ChatGPT, Cursor and other MCP clients. Four SObject servers read, create, update and delete any standard or custom object the signed-in user can already touch. Salesforce lists no separate MCP price: it ships to Enterprise Edition orgs and above, and free Developer Edition orgs get it at no cost. It cannot find people who are not in your org yet, and it cannot put a verified email or phone number on a record. Cleanlist AI publishes this review and also makes an MCP server, which the worked flow below uses. Cleanlist AI's plans are on the pricing page.
Facts checked October 3, 2026. Every Salesforce fact below comes from Salesforce's Hosted MCP Servers developer guide and two posts on the Salesforce Developers blog, each read on October 3, 2026. This review did not run the server against a production org, so it carries no speed or accuracy numbers.
What is the Salesforce MCP server?
The Salesforce MCP server is a Salesforce-managed endpoint that turns your org's data and logic into tools an AI client can call. MCP, the Model Context Protocol, is an open standard for connecting AI applications to outside systems. Salesforce configures the server once in Setup, and any MCP client that supports OAuth can connect to it.
Salesforce ships two kinds of hosted server:
- Standard servers. Pre-built by Salesforce with a fixed tool set. They are off by default and an admin turns them on. The four SObject servers cover records. Product servers cover Data 360, Tableau Next, Headless 360 (beta) and CRM Analytics (beta).
- Custom servers. Your admin exposes Flows, Apex invocable actions,
@AuraEnabledmethods, Apex REST endpoints, Named Queries and API Catalog endpoints as tools, without writing connector code. Prompt Builder templates can show up as MCP prompts in clients that support them.
Salesforce's own pitch for it: a rep preparing for a quarterly review asks the chat for account history, open opportunities, recent cases and the stakeholder map, and never opens a report.
Does Salesforce have its own MCP server?
Yes, two of them, built for different people.
| Hosted MCP Servers | Salesforce DX MCP Server | |
|---|---|---|
| Runs on | Salesforce infrastructure | Your machine |
| Sign-in | OAuth 2.0, per user | Salesforce CLI credentials |
| Tools | Records, Flows, Apex actions, queries | 60+ developer tools for metadata, Apex tests and Lightning Web Components |
| For | Sales, RevOps and anyone working with org data from a chat | Developers building and deploying on Salesforce |
This review covers the hosted servers, because that is the one a sales or RevOps team means when it searches "Salesforce MCP". The hosted service started as a pilot in spring 2025, went to beta in October 2025 and reached general availability in April 2026. Teams that connected during the beta have to reconnect: the GA release changed the server URLs, turned servers off by default and replaced four OAuth scopes with two (mcp_api and refresh_token). Community-built Salesforce MCP servers also exist on GitHub. They are separate projects with their own security models.
Is the Salesforce MCP server free?
Salesforce prints no separate price for hosted MCP on any page read for this review. Access depends on your org:
- Enterprise Edition and above. Salesforce's GA announcement calls hosted MCP "a production-ready capability for every Enterprise Edition org and above."
- Developer Edition. The free Developer Edition includes hosted MCP servers "at no cost," per Salesforce's April 2026 Developer Edition post.
- Professional Edition. Salesforce's troubleshooting guide says the org must support API access, naming "Developer or Enterprise, or Professional with API access enabled."
Two costs sit outside Salesforce. Your AI client (Claude, ChatGPT or Cursor) has its own plan. And the server only moves data you already own, so any new contact data comes from somewhere else.
Salesforce's reference documents two size limits that matter for prospecting work: soqlQuery handles at most 50,000 records per transaction, and find returns at most 2,000 records.
How do I turn on Salesforce MCP in Claude and ChatGPT?
Salesforce puts setup at under 30 minutes. You need System Administrator or equivalent permissions in the org.
- Turn on the servers. In Setup, search Quick Find for "MCP Servers" and open it under API Catalog. Toggle on the servers your team needs. A server can take up to two minutes to go live.
- Create an External Client App. Open External Client App Manager, click New External Client App, and tick Enable OAuth. Set the callback URL for your client:
https://claude.ai/api/mcp/auth_callbackfor Claude, or the URL ChatGPT shows in its advanced settings. Add the scopesmcp_apiandrefresh_token, select "Issue JSON Web Token (JWT)-based access tokens for named users," and save. The app can take up to 30 minutes to work. Copy its consumer key. Connected Apps do not work for MCP. - Connect Claude. In Claude, open Customize, then Connectors, click the plus sign and choose Add custom connector. Paste a server URL such as
https://api.salesforce.com/platform/mcp/v1/platform/sobject-reads. Under Advanced settings, paste the consumer key into OAuth Client ID, click Add, then Connect and log in to Salesforce. - Or connect ChatGPT. In ChatGPT, open Settings, then Apps, then Create App. Paste the server URL, set Registration Method to "User-defined OAuth client" under Advanced settings, paste the consumer key, and copy ChatGPT's callback URL back into the External Client App. In a chat, pick Salesforce under the plus button.
Sandbox and scratch orgs use the same URLs with /sandbox/ after /v1/. Salesforce recommends testing with Postman before connecting a chat client, because Postman calls the tools directly and shows the raw JSON.
The tools it exposes, and what each one is good for
Each SObject server is a fixed tool set. Pick the narrowest one that does the job.
| Server | URL path | What it allows | Best for |
|---|---|---|---|
| SObject Reads | platform/sobject-reads | Schema, SOQL, search and related records. No changes | Pipeline questions, meeting prep, a first rollout |
| SObject Mutations | platform/sobject-mutations | Reads plus create and update. No delete | Logging notes, creating leads and tasks, updating stages |
| SObject Deletes | platform/sobject-deletes | Delete only | A separate, deliberate cleanup process |
| SObject All | platform/sobject-all | Create, read, update, delete, query, search, relationships | Power users the admin already trusts |
The tools on SObject All, as Salesforce documents them:
getObjectSchemareturns a compact index of every object, or full field details for one object, plus any guidance your admin wrote.soqlQueryruns a SOQL query. It is the main way to read data.findruns a SOSL text search across objects, by name, email or phone fields.getUserInforeturns the signed-in user's ID, role, manager and time zone, so "my accounts" works.listRecentSobjectRecordsreturns the records of one type the user viewed or changed recently.getRelatedRecordswalks from a parent record to its children, such as an Account's Contacts.createSobjectRecordandupdateSobjectRecordwrite one record by object name and field values.updateRelatedRecordupdates a parent record from a child, up to five levels up.deleteSobjectRecordanddeleteRelatedRecordsend records to the Recycle Bin.
What it cannot do
The Salesforce MCP server acts on the records in your org. That is the whole scope, and it shapes what you can ask of it.
- Find people who are not in Salesforce yet. No tool searches outside your org. "Find 50 VPs of Finance at my target accounts" returns only the ones someone already entered.
- Verify an email or look up a phone number. It writes whatever values it is given.
- Create records in bulk in one call. Salesforce documents
createSobjectRecordwith one record body per call, so 50 new leads means 50 tool calls. - Undo a delete. Deleted records sit in the Recycle Bin for up to 15 days, and there is no undelete tool over MCP.
- Send email or enroll a lead in a cadence out of the box. Custom servers can expose your own Flows and Apex actions if your team has built them.
- Pull very large sets.
findstops at 2,000 records and SOQL at 50,000 per transaction.
A worked flow: Salesforce MCP and Cleanlist AI MCP together
The job most sales teams want from a chat is the one the Salesforce server cannot do alone: find the right people at accounts you own, skip the ones already in Salesforce, put verified contact data on the rest and create them as leads. Pair Salesforce's server with a data server and it becomes one prompt. Cleanlist AI makes the data server used here, so read this section as a vendor's example.
Setup. Two connectors in Claude: Salesforce's sobject-mutations server and Cleanlist AI's MCP server (included from Cleanlist AI's Starter plan).
The prompt. "Find VPs and Directors of Sales and RevOps at the prospect accounts I own, skip anyone already in Salesforce, get verified work emails and phone numbers, and create them as leads with Lead Source set to Outbound."
What Claude runs:
- Salesforce
soqlQuerypulls your accounts:SELECT Id, Name, Website FROM Account WHERE Owner.Email = 'you@yourcompany.com' AND Type = 'Prospect' LIMIT 200. A second query pulls the Contacts and Leads already at those companies. - Cleanlist AI
search_peoplesearches those exact company domains for the titles you named. Searching costs nothing. On Cleanlist AI plans with Salesforce sync, the search can also drop anyone already in your Salesforce before it runs. - Claude compares the results with what Salesforce returned and removes matches. For a borderline name it calls Salesforce
findwithFIND {Jordan Lee} IN NAME FIELDS RETURNING Contact(Id, Name), Lead(Id, Name). - Cleanlist AI
create_listandadd_leads_to_listsave the survivors.estimate_costreturns a signed quote, so the next step cannot spend past it.enrich_listruns the waterfall for work emails and phone numbers, andenrich_statuswaits for it to finish. A person with nothing found costs nothing. - Salesforce
getObjectSchemawithLeadreads the required fields and the valid Lead Source values.createSobjectRecordthen creates each lead with first name, last name, title, company, email, phone and Lead Source. - Claude reports back: leads created, people skipped as already in Salesforce, and people with no verified email.
Keep Claude's write tools on "needs approval" for the first few runs. Fifty leads means fifty create calls, and you want to see the first five before the rest go in. Teams on Cleanlist AI's Pro plan can skip step 5: Cleanlist AI's two-way Salesforce sync writes the enriched rows to Leads, Contacts or Accounts and creates a missing Account. To run the whole thing every Monday without a prompt, ask Clu, Cleanlist AI's GTM agent, to turn it into an agent that posts each run to Slack (agents start on Pro). See how agents work and the Cleanlist AI MCP setup.
Salesforce MCP vs HubSpot MCP vs Apollo and ZoomInfo MCP
CRM servers act on the records you already have. Data servers find new ones. Most teams that prospect from a chat connect one of each.
| MCP server | Endpoint | Works on | Writes | What it costs | Best for |
|---|---|---|---|---|---|
| Salesforce | api.salesforce.com/platform/mcp/v1/ | Your Salesforce org | Create, update and delete, by server | No separate price listed; Enterprise Edition and above, free in Developer Edition | Teams whose system of record is Salesforce |
| HubSpot | mcp.hubspot.com | Your HubSpot account | Create and update records and activities; no delete | HubSpot's connectors are on all HubSpot plans | Teams whose system of record is HubSpot |
| Apollo.io | mcp.apollo.io/mcp | Apollo's database and workspace | Contacts, accounts, deals, sequences, one-off emails | Any Apollo plan; enrichment spends Apollo credits | Teams that already sequence from Apollo |
| ZoomInfo | mcp.zoominfo.com/mcp | ZoomInfo's database | Read-only toward your CRM | 1 data credit per newly enriched record | Enterprise account research |
HubSpot facts are from HubSpot's developer docs and knowledge base, read October 3, 2026. Apollo and ZoomInfo facts are from each vendor's docs, read October 1, 2026, and covered in full in the Apollo MCP server review, the ZoomInfo MCP server review and the Clay MCP server review. The HubSpot side gets the same treatment in the HubSpot MCP server review, and the full field sits in the best MCP servers for sales and GTM.
Security and permissions
Salesforce built the server around the permission model admins already run.
- Every call runs as the signed-in user. Field-level security, object permissions and sharing rules apply to each tool call, and the user's name shows in the audit trail.
- A separate OAuth scope.
mcp_apigrants MCP access without granting Salesforce's existing REST APIs. - Off by default. No server answers until an admin turns it on in Setup.
- Scoped servers. Reads-only, create-and-update, and delete-only servers let you hand out exactly the access a team needs.
For production, Salesforce's guide lists five optional hardening steps on the External Client App: require a client secret for web-based clients, limit access to users with a specific permission set, restrict connections to known IP ranges, cut refresh-token validity to 30 days or less with rotation on, and enable single logout so a revoked Salesforce session ends the MCP session too. Salesforce's own advice for a first rollout: start with sobject-reads in a sandbox.
Who should use it
Salesforce's MCP server is the right pick for a Salesforce team that wants reps and managers to ask pipeline questions, prep for meetings and log activity from Claude or ChatGPT, under the permissions the admin already set. It is also the cleanest way to give an internal agent safe write access to Salesforce, because the tool set is fixed and every action is audited.
It does less for a team whose bottleneck is new pipeline. It knows only what your reps have already entered, so it needs a data source beside it for prospecting.
Where Cleanlist AI fits
Cleanlist AI is the data side of the worked flow above: People Search across its people index, waterfall enrichment for work emails and phone numbers, two-way Salesforce sync on Pro, and an MCP server from Starter. Clu, Cleanlist AI's GTM agent, runs the same flow as a scheduled agent. The box below is the disclosed vendor entry, with the numbers from Cleanlist AI's own facts file.
Our product
Cleanlist
Best for: B2B teams under 300 people who want verified emails and phone numbers from 25+ providers in one waterfall, paying only for results.
Cleanlist AI publishes this page. Accuracy figures are from our own benchmark, not a third-party test.
Cleanlist AI runs waterfall enrichment across 25+ data providers in sequence and stops at the first deliverable result, at 1 credit per verified work email and 10 per phone number. A missed email or phone number costs nothing. It returns 98% verified work emails and 85% phone numbers on the Cleanlist AI 500-Lead Enrichment Benchmark, which is our own test run on a 500-lead sample. Plans start at $49 per seat a month.
Clu, Cleanlist AI's GTM agent, turns one sentence into an agent that searches 1B+ profiles, enriches and verifies every person it finds, adds them to a sequence and posts each run to Slack, every week or on a CRM trigger.
- Product
- Plans
Free plan 50 credits a month. Starter $49 and Pro $89 per seat a month, and every seat adds its credits to one shared balance. Enterprise is custom. 25% off on annual billing.
- Credits
- Verified work email1
- Phone number10
- Both on one row11
- Validation0.5
- AI qualification5
- Trial
14 days of Pro, free: 250 credits, 3 seats, agents, Sequences and Clu in Slack.
- Fits when
- You prospect from Claude or ChatGPT and want the people Salesforce is missing, with verified emails and phone numbers
- You want new leads written straight into Salesforce Leads, Contacts or Accounts by two-way sync on Pro
- You want the same search to run every week as an agent that posts to Slack
- Pairs with
- Salesforce's own MCP server, for reading and updating the records you already have
- Your sequencer, if your team already runs one
Verdict
Salesforce's hosted MCP server is the official, admin-governed way to put your org inside Claude, ChatGPT or Cursor, with no separate price listed for Enterprise Edition and above. Turn on sobject-reads first, move to sobject-mutations when a team needs to write, and keep deletes behind their own server. For prospecting, pair it with a data server so the chat can find people your org does not have yet. Cleanlist AI's plans and MCP access are on the pricing page.
Frequently asked questions
Is there an official Salesforce MCP server?
Yes. Salesforce Hosted MCP Servers are Salesforce's own, generally available since April 2026. Salesforce also publishes the Salesforce DX MCP Server, a local server for developers with 60+ tools for metadata, Apex tests and Lightning Web Components.
Does the Salesforce MCP server work with ChatGPT?
Yes. Salesforce lists ChatGPT as a tested client, connected through ChatGPT's developer mode and apps with a user-defined OAuth client. Claude, Cursor, Postman and Agentforce Vibes are also tested.
Can the Salesforce MCP server delete records?
Only through the SObject All or SObject Deletes servers, and only records the user can delete in Salesforce. Deleted records go to the Recycle Bin for up to 15 days, and there is no undelete tool over MCP.
Can the Salesforce MCP server find new leads?
No. It reads and writes the records already in your org. To find people who are not in Salesforce yet, connect a data server beside it, such as Apollo's or ZoomInfo's.
What is the Salesforce MCP server URL?
Production orgs use https://api.salesforce.com/platform/mcp/v1/ followed by the server name, for example platform/sobject-all. Sandbox and scratch orgs add sandbox/ after v1/.
Sources
- Salesforce, Salesforce Hosted MCP Servers: Get Started, read October 3, 2026
- Salesforce, Standard MCP Servers Reference, SObject All, SObject Mutations and SObject Reads, read October 3, 2026
- Salesforce, Activate MCP Servers, Create an External Client App and Transition from Beta, read October 3, 2026
- Salesforce, Connect MCP Clients, Configure Claude and Configure ChatGPT, read October 3, 2026
- Salesforce, Server Connection Failures and Products Supporting MCP, read October 3, 2026
- Salesforce Developers Blog, Salesforce Hosted MCP Servers Are Now Generally Available, April 2026, read October 3, 2026
- Salesforce Developers Blog, New in Salesforce Developer Edition: Agentforce Vibes IDE, Claude 4.5, MCP, April 2026, read October 3, 2026
- HubSpot, Integrate AI tools with the HubSpot MCP server, read October 3, 2026
- Apollo.io, Apollo MCP developer docs, and ZoomInfo, ZoomInfo MCP docs, read October 1, 2026

