Skip to content

salesforce: recommend Headless 360 and label admin-set values - #520

Closed
minupalaniappan wants to merge 1 commit into
mainfrom
minu/salesforce-headless-360
Closed

minupalaniappan wants to merge 1 commit into
mainfrom
minu/salesforce-headless-360

Conversation

@minupalaniappan

@minupalaniappan minupalaniappan commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

What this PR delivers

Points the Salesforce plugin at Salesforce's new Headless 360 (Beta) hosted MCP server and makes it clear that a Salesforce admin sets the server URL and Consumer Key once for the team. Existing installs don't change: mcp.json, the server key, the variable names, the scopes, and the OAuth flow are all untouched.

Changes

  • plugin.json 1.1.0:
    • The SALESFORCE_MCP_URL description recommends the Headless 360 production and sandbox URLs and notes that SObject and custom URLs keep working.
    • Both variable titles now say "(set by your Salesforce admin)", and the Consumer Key description tells members they only need to sign in.
    • The homepage now points to the Headless 360 docs.
  • README:
    • New "Who does what" table (admin vs member).
    • Headless 360 is the recommended server, with its activation step and the API v67+ requirement. The SObject and custom server tables are kept.
    • New "Switching an existing setup to Headless 360" section.
    • New approval guidance for dispatch.
    • New troubleshooting row for a member who is prompted for setup values.
  • CHANGELOG 1.1.0.

Why existing users are safe

  • Saved values are kept. Stored plugin variables are keyed by name, and the names didn't change.
  • The URL is still configurable. Hard-coding Headless 360 would break sandbox orgs, custom servers, teams that chose sobject-reads on purpose, and orgs that haven't activated the Beta.
  • Same OAuth setup. Headless 360 publishes the same protected-resource metadata as sobject-all (authorization server login.salesforce.com, scopes mcp_api and refresh_token), so the same External Client App works.
  • The local "Salesforce DX" server isn't affected. Users who configured @salesforce/mcp themselves in mcp.json run a local server this plugin doesn't ship.

Out of scope

  • A CLIENT_SECRET variable. It is deliberately not added. Unset placeholders stay literal (${CLIENT_SECRET}). Any defined client_secret also makes the MCP SDK pick client_secret_basic, because Salesforce doesn't advertise none. As a result, every existing install without a secret would send a bogus secret and fail at the token step. Supporting an optional secret first needs Cursor to drop blank or unresolved secrets.
  • An "Ask your team admin to configure Salesforce" notice for members. The variable schema has no admin-only flag, and only SharePoint has that notice today, so this needs a client change.

QA plan

Setup: a Salesforce Developer Edition org with an External Client App configured per the README, and Headless 360 activated.

  1. As an admin, set the Headless 360 URL and Consumer Key on a team marketplace. A non-admin member installs the plugin, isn't asked for values, and signs in.
  2. A member on a team with no admin configuration is asked for the URL and Consumer Key, and the field labels say an admin sets them.
  3. Run on the Cursor desktop app, Cloud Agents / web, and Grok Bot desktop.
  4. Run the tools:
    • discover → describe → dispatch_readonly, for example "show my open opportunities".
    • A dispatch write, for example "log a call on account X", which should ask for approval before it runs.
  5. Run against a sandbox org with the sandbox Headless 360 URL.
  6. Check that an existing sobject-all install keeps its URL and sign-in after 1.1.0 is indexed, with tools unchanged.
  7. Switch that install to the Headless 360 URL and note whether it asks for sign-in again.
  8. Check the error cases:
    • Headless 360 not activated.
    • JWT access tokens turned off ("Invalid token").
    • A user with limited field-level security.
    • A token refresh after the access token expires.

node scripts/validate-plugins.mjs passes.


Note

Low Risk
Docs and plugin manifest text only; existing OAuth and MCP configuration behavior is unchanged.

Overview
Bumps the Salesforce Cursor plugin to 1.1.0 with documentation and metadata only—no changes to mcp.json, variable names, OAuth scopes, or the MCP wiring.

plugin.json now points the homepage and SALESFORCE_MCP_URL guidance at Headless 360 (Beta) (production/sandbox URLs, activation note) while stating that existing SObject and custom URLs still work. Variable titles/descriptions clarify that a Salesforce admin sets the server URL and Consumer Key once for the team; members only sign in. Adds the headless-360 keyword.

README expands install/admin flow: “Who does what” table, Headless 360 as the recommended server (tools, API v67+, migration from SObject URLs), team marketplace configuration, dispatch approval guidance, and extra troubleshooting/docs links.

CHANGELOG records 1.1.0.

Reviewed by Cursor Bugbot for commit 284d73f. Bugbot is set up for automated code reviews on this repo. Configure here.

Bump to 1.1.0. Recommend the Headless 360 (Beta) server URLs, label the
server URL and Consumer Key as admin-set team values, and document admin
setup, migration, and dispatch approvals. mcp.json, variable names, and
the OAuth flow are unchanged so existing installs keep working.
@minupalaniappan

Copy link
Copy Markdown
Collaborator Author

Superseded by #521, which adds Headless 360 as a separate plugin so the existing salesforce plugin stays unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant