Salesforce for AI agents

Salesforce is the widely used CRM that sales, service, and marketing teams run their pipelines, accounts, and customer records on. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

CRMOAuth 2.0MCP + RESTsalesforce.com
AUDIT LOG · SALESFORCEPOLICY: acme-support
09:41:07 · claude · u_8f2read
salesforce.list_leads
List leads✓ allowed · 212ms
09:41:08 · claude · u_8f2read
salesforce.get_api
Get API resources by version✓ allowed · 164ms
09:41:09 · claude · u_8f2write
salesforce.create_lead
Create lead✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
salesforce.delete_file
Delete file✕ blocked · policy: deny
EVERY SALESFORCE CALL, ON THE RECORD
01 · USE CASES

What agents do in Salesforce.

01

Create or update an account record

Adds a new Salesforce account or updates fields on an existing one after a deal changes stage.

02

Look up a record before acting

Reads an opportunity or contact record to confirm the current owner and stage before making a change.

03

Clone an opportunity only after confirmation

Duplicates an opportunity with its products once a rep confirms the renewal or upsell should proceed.

02 · ACTIONS

224 Salesforce actions, graded by risk.

Every Salesforce action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

124

Look things up. Allowed by default.

  • salesforce.get_api
    Get API resources by version
  • salesforce.get_app
    Get an app
  • salesforce.get_apps
    Get apps
  • salesforce.get_lead
    Get lead
  • salesforce.get_note
    Get note
  • salesforce.get_theme
    Get theme
  • salesforce.query_all
    Query All (including deleted)
  • salesforce.get_report
    Get report metadata
  • salesforce.list_leads
    List leads
  • salesforce.list_notes
    List notes
  • salesforce.query_more
    Query more (next page of SOQL results)
  • salesforce.get_account
    Get account
  • salesforce.get_contact
    Get contact
  • salesforce.get_support
    Get support knowledge
  • salesforce.get_campaign
    Get campaign
  • salesforce.list_reports
    List reports
+ 108 MORE

write

82

Create and change things. Allow, or ask the user first.

  • salesforce.send_email
    Send email
  • salesforce.create_lead
    Create lead
  • salesforce.create_note
    Create note
  • salesforce.create_task
    Create task
  • salesforce.update_lead
    Update lead
  • salesforce.update_note
    Update note
  • salesforce.update_task
    Update task
  • salesforce.update_record
    Update a record
  • salesforce.create_account
    Create account
  • salesforce.create_contact
    Create contact
  • salesforce.update_account
    Update account
  • salesforce.update_contact
    Update contact
  • salesforce.create_a_record
    Create a record
  • salesforce.create_campaign
    Create campaign
  • salesforce.send_mass_email
    Send mass email
  • salesforce.update_campaign
    Update campaign
+ 66 MORE

destructive

18

Delete, cancel or archive. Ask first, or deny outright.

  • salesforce.delete_file
    Delete file
  • salesforce.delete_lead
    Delete lead
  • salesforce.delete_note
    Delete note
  • salesforce.delete_account
    Delete account
  • salesforce.delete_contact
    Delete contact
  • salesforce.delete_sobject
    Delete sObject record
  • salesforce.delete_campaign
    Delete campaign
  • salesforce.delete_job_query
    Delete job query
  • salesforce.delete_opportunity
    Delete opportunity
  • salesforce.remove_from_campaign
    Remove from campaign
  • salesforce.remove_note_object_by_id
    Remove note object by id
  • salesforce.remove_opportunity_by_id
    Remove opportunity by id
  • salesforce.delete_sobject_collections
    Delete multiple records (SObject Collections)
  • salesforce.remove_campaign_object_by_id
    Remove campaign object by id
  • salesforce.delete_a_lead_object_by_its_id
    Delete a lead object by its id
  • salesforce.remove_a_specific_contact_by_id
    Remove a specific contact by id
+ 2 MORE
03 · HOW IT WORKS

Salesforce in three steps.

  1. 01Your users connect SalesforceThey sign in to Salesforce on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create lead” can wait for the user, and “delete file” can be denied outright.
  3. 03Any agent can actYour agent calls Salesforce through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('salesforce', {
  read: 'allow',
  write: 'ask',        // create_lead
  destructive: 'deny',  // delete_file
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Salesforce connects.

Users sign in to Salesforce on Arc0 Connect and approve the scopes you request. Build with Arc0’s Salesforce OAuth app, or bring your own so the Salesforce consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Salesforce connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0 · OAuth 2.0 client credentials
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Salesforce from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Salesforce and Arc0, answered.

Q01

Can I use Salesforce with Claude, ChatGPT or Cursor?

Yes. Connect Salesforce to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Salesforce actions you allow.

Q02

How do users connect Salesforce?

Users sign in to Salesforce on Arc0 Connect and approve the scopes you request. Build with Arc0’s Salesforce OAuth app, or bring your own so the Salesforce consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Salesforce actions can my agent take?

224 in total: 124 read, 82 write and 18 destructive, such as “create lead”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Salesforce?

Yes. Actions like “delete file” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Salesforce too?

Yes. The same Salesforce connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Salesforce into your agent.

Your users connect Salesforce once, under your brand. Your agent gets 224 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan