Skip to content

Docs · Claude · Guide

Setting up and troubleshooting Claude with Salesforce MCP

For salesforce admins, it and security.

Short answer

Most failed Claude to Salesforce MCP connections come down to the External Client App settings: the OAuth scopes, PKCE and the run-as user. Add the scope that allows API access, leave run-as empty so each person's own permissions apply, create one connector per access level, and test read-write in a clearly named sandbox first.

External Client App settings to check

  • OAuth scopes. Include "Manage user data via APIs (api)" along with the scopes Salesforce's MCP setup guide lists. Some public walkthroughs leave it out, and its absence is the most common reason a connection authorizes but then fails.
  • PKCE required for the flow the connector uses.
  • Refresh token policy set so people don't have to reconnect every session, in line with your security policy.
  • No run-as user. Leave it empty so Claude acts with each signed-in person's permissions. A run-as user gives everyone that user's access.
  • IP and session policies that allow Claude's servers to reach the org, if your org restricts login IPs.

Connectors in Claude

  • Create one connector per access level, for example read-only for everyone and read-write for a small group, and name each one so people know which they're using.
  • Connect read-write to a sandbox first, with "sandbox" in the connector name.
  • On Claude Team, check which members can see and use each connector; on Enterprise, restrict connectors to groups.

Troubleshooting

SymptomCheck
Authorization succeeds, then every call failsMissing api scope, or the user's profile lacks API Enabled
Some objects or fields are missingThe user's object and field permissions; some managed package objects may not be exposed
Connector shows as connected but not in the chatRestart the Claude desktop app and check the connector is enabled for the conversation
Works for admins, fails for usersProfile or permission set differences; test with a real user, not an admin

Official documentation

Frequently asked questions

Why does Claude connect to Salesforce but then fail on every request?

Usually the External Client App is missing the api scope (Manage user data via APIs), or the user's profile doesn't have API Enabled. Add the scope, reauthorize and test again.

Should the Salesforce MCP connection use a run-as user?

No. Leave run-as empty so Claude acts with each signed-in person's own Salesforce permissions. A shared run-as user gives everyone that user's access.

Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.

Last reviewed October 9, 2026 by the Vantage Point team. Browse all docs