Short answer
Most failed Claude to Salesforce MCP connections come down to the External Client App settings: the OAuth scopes, PKCE and the run-as user. Add the scope that allows API access, leave run-as empty so each person's own permissions apply, create one connector per access level, and test read-write in a clearly named sandbox first.
External Client App settings to check
- OAuth scopes. Include "Manage user data via APIs (api)" along with the scopes Salesforce's MCP setup guide lists. Some public walkthroughs leave it out, and its absence is the most common reason a connection authorizes but then fails.
- PKCE required for the flow the connector uses.
- Refresh token policy set so people don't have to reconnect every session, in line with your security policy.
- No run-as user. Leave it empty so Claude acts with each signed-in person's permissions. A run-as user gives everyone that user's access.
- IP and session policies that allow Claude's servers to reach the org, if your org restricts login IPs.
Connectors in Claude
- Create one connector per access level, for example read-only for everyone and read-write for a small group, and name each one so people know which they're using.
- Connect read-write to a sandbox first, with "sandbox" in the connector name.
- On Claude Team, check which members can see and use each connector; on Enterprise, restrict connectors to groups.
Troubleshooting
| Symptom | Check |
|---|---|
| Authorization succeeds, then every call fails | Missing api scope, or the user's profile lacks API Enabled |
| Some objects or fields are missing | The user's object and field permissions; some managed package objects may not be exposed |
| Connector shows as connected but not in the chat | Restart the Claude desktop app and check the connector is enabled for the conversation |
| Works for admins, fails for users | Profile or permission set differences; test with a real user, not an admin |
Official documentation
Frequently asked questions
Why does Claude connect to Salesforce but then fail on every request?
Usually the External Client App is missing the api scope (Manage user data via APIs), or the user's profile doesn't have API Enabled. Add the scope, reauthorize and test again.
Should the Salesforce MCP connection use a run-as user?
No. Leave run-as empty so Claude acts with each signed-in person's own Salesforce permissions. A shared run-as user gives everyone that user's access.
Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.
