Clientell Salesforce MCP

Salesforce MCP server: give your AI assistant a live map of your Salesforce org (objects, fields, flows, Apex, permissions). Ask questions, trace dependencies, and make changes you approve first.

Hosted MCP Server

npx add-mcp 'https://mcp.clientell.ai/mcp'

Installs into Claude Code, Codex, Cursor and more

Documentation

Scope

Twelve connectors, all read live. Salesforce, Slack, Jira, GitHub, Gmail, Google Calendar, Google Drive, Notion, Microsoft Teams, SharePoint, Outlook Mail and Outlook Calendar are available today. Each one reads the source system when you ask, through your own grant. See the connector reference.

Connect your workspace and register the server yourself. The setup guide uses Claude Code, where Clientell is built and verified end to end. Any Streamable HTTP MCP client works too, including Cursor, VS Code, ChatGPT and Gemini, and the guide has config snippets for the common ones.

Contents · 19 sections

Know your org. Check the change. Keep control.

Ask your AI client what depends on a field, inspect a live record when needed, and keep decisions across conversations. The hosted MCP server connects these three parts. There is no local server to install.

metadata index live reads, read-only on your own connection approved deploys Your AI client Claude Code, Cursor, VS Code Clientell MCP answers your questions Context Graph your org's metadata map Your sf CLI runs on your machine Salesforce org your records live here

Asking a question

  1. Your AI client Claude Code, Cursor, VS Code
  2. Clientell MCP answers your questions
  3. Context Graph your org's metadata map
  4. metadata index
  5. Salesforce org your records live here

Reading live records

  1. Your AI client Claude Code, Cursor, VS Code
  2. Clientell MCP read-only, nothing stored
  3. via Clientell's auth service, on your own connection
  4. Salesforce org your records live here

Deploying a change

  1. Your AI client Claude Code, Cursor, VS Code
  2. Your sf CLI runs on your machine
  3. approved deploys
  4. Salesforce org your records live here

Your AI client asks Clientell. Clientell answers from the Context Graph and reads live records on your own Salesforce connection. Approved changes deploy through your own sf CLI.

1 · The graph

Trace dependencies before changing metadata.

Objects, fields, flows, Apex, validation rules, profiles and permission sets, plus the references between them. Ask what references a field before changing it. Rebuild the graph in one call whenever you want. It holds no record contents.

2 · The live session

Check live records with your own permissions.

Lookups run when you ask, through Clientell’s auth service on your own Salesforce connection. Records pass straight back to your client and are never written to the graph.

3 · Memory

Carry forward context you choose to save.

You or the model explicitly write entries. Corrections, versions and time-based expiry keep that context inspectable. Nothing is saved automatically from your activity. See Memory.

1 Draft the change edit as metadata 2 Check the blast radius what it touches 3 Your approval you say yes 4 Deploy through your sf CLI on your machine 5 Verify confirm it landed deploy_guard when Clientell prepares the deploy for Profiles, Permission Sets and Sharing Rules: refuses unsafe replace-not-merge payloads

  1. Draft the change edit as metadata
  2. Check the blast radius what it touches
  3. Your approval you say yes
  4. Deploy through your sf CLI on your machine deploy_guard When Clientell prepares a Profile, Permission Set or Sharing Rules deploy, it refuses unsafe replace-not-merge payloads.
  5. Verify confirm it landed

Every change is drafted, checked for what it touches, and deployed only after you approve. When Clientell prepares a Profile, Permission Set or Sharing Rules deploy, deploy_guard refuses payloads that would silently wipe existing entries.

Call all twelve connectors directly over MCP from your client. No separate Clientell agent is required.

Deep org context, with clear boundaries.

See what your client can act on, where the data stays, and which safeguards apply before a change reaches Salesforce.

Indexed stored in the Context Graph names IDs relationships structure only Read live fetched only when you ask record data your connection → your org as you, never stored Never stored not kept by Clientell record contents message bodies stays in your org

  1. Indexed stored in the Context Graph
    • names
      • IDs
      • relationships structure only
  2. Read live fetched only when you ask
    • record data through your own Salesforce connection, never stored
  3. Never stored not kept by Clientell
    • record contents
      • message bodies stays in your org

The graph holds structure. Record data is read live and never stored.

What it does

  • Maps Salesforce metadata and dependencies so you can see what a change would affect before making it.
  • Reads live Salesforce records on demand, read-only, through Clientell's auth service on your own Salesforce connection and permissions. Records pass through to your client and are not stored.
  • Drafts changes and checks their blast radius. After your approval, your AI client deploys through your own Salesforce CLI session. When Clientell prepares a deploy, deploy_guard checks it and refuses unsafe replace-not-merge payloads for Profiles, Permission Sets and Sharing Rules.
  • Reads twelve connectors live at question time, through your own grant, so connector answers are current by design.
  • Stamps every graph answer with its last_graph_build time, and pairs Flow, Apex and validation-rule answers with a ready-to-run live check.
  • Gives MCP-compatible clients tools over Streamable HTTP with bearer auth.
  • Isolates each workspace from every other workspace. Inside a workspace, everyone sees the same org map, because graph queries do not apply each person's individual Salesforce record-level or field-level permissions. You decide who is in the workspace.
  • Keeps explicitly written work context with corrections, versions and expiry.

Deliberate design choices

  • Keeps Salesforce record contents and message bodies out of the index. Connectors read them live when you ask.
  • Leaves deploys with you. Changes run through your own local sf CLI session, which Clientell never sees. Live record reads run only as the person who connected the org, so a teammate cannot read through your connection.
  • Proves a duplicate-record merge is safe before anything is deleted. merge_duplicate_records verifies every record ID against the org and drafts the merge plan; the merge itself runs through your own sf session.
  • Puts you in charge of the confirmation policy for connector writes. Slack, Jira and GitHub actions run through your AI client's own tool-approval controls.
  • Rebuilds the Salesforce graph on demand, in one call, whenever you want, and tells you how fresh each answer is.

Replace, not merge your deploy · 1 entry live org, after deploy Profile Sales_Rep Account · edit Account · edit kept Opportunity · edit Case · read Lead · read 3 existing entries silently deleted deploy_guard refuses this payload The safe path 1 Read the live definition Sales_Rep exactly as it is now 2 Merge your change in Account · edit joins the other 3 3 Write the full definition all 4 entries, nothing lost deploy_guard lets it through

Replace, not merge

  1. Your deploy: Profile Sales_Rep carries 1 entry: Account · edit
  2. replaces the whole definition
  3. Live org, after deploy
    • Account · edit, kept
      • Opportunity · edit deleted
      • Case · read deleted
      • Lead · read deleted
  4. deploy_guard refuses this payload applies to Profile, PermissionSet and SharingRules

The safe path

  1. 1. Read the live definition Sales_Rep exactly as it is now
  2. 2. Merge your change in Account · edit joins the other 3
  3. 3. Write the full definition all 4 entries, nothing lost
  4. deploy_guard lets it through all 4 entries, nothing lost

Illustrative example. When Clientell prepares a deploy, deploy_guard refuses payloads that would silently wipe existing permissions or sharing rules.

See the blast radius before you make a change.

The Context Graph maps your org’s components and their references. Ask what depends on Account.Custom_Segment__c before you delete it. Get the affected flows and permissions from the graph, not a series of live API calls.

reads it checks or shows it runs on it Account.Industry picklist field Flows Set_Account_Tier Apex classes AccountService.cls Validation rules Industry_Required Page layouts Account Layout Reports Pipeline by Industry Reports Accounts by Industry

  • Account.Industry picklist field

Ring 1: runs on it

  • Flows Set_Account_Tier
  • Apex classes AccountService.cls

Ring 2: checks or shows it

  • Validation rules Industry_Required
  • Page layouts Account Layout

Ring 3: reads it

  • Reports Pipeline by Industry
  • Reports Accounts by Industry

Illustrative example. Before you change a field, see everything it touches.

The index

See the dependencies without copying customer records.

Ask which flow touches a field or which profile reaches an object. The index holds names, identifiers and relationships, not Salesforce record contents or message bodies. When you need the actual words, connectors read them live from the source system, as you.

The Salesforce graph

Query a read-only Salesforce graph.

Queries use the database’s read-only execution path. A graph query cannot write to the index, so you can inspect dependencies without changing the map you rely on.

Your org

Deploy with your own Salesforce credentials.

Clientell patches and audits a proposed change. After you approve, your AI client runs the deployment through your own sf CLI session, with your permissions. Clientell never sees that session.

What the graph indexes

Objects, fields, flows, Apex, validation rules, profiles and permission sets, with their references. Ask which flow writes to a field, which profiles can edit it, or what a deletion would break. The graph answers structural questions without reading customer records.

belongs to writes references checks reads grants access to grants access to Fields Account.Industry Objects standard + custom Flows record-triggered Apex classes, triggers Validation Rules save-time checks Reports and dashboards Profiles baseline access Permission Sets extra access

What links to what

  • Fields belong to Objects
  • Flows write Fields
  • Apex references Fields
  • Validation Rules check Fields
  • Reports read Fields
  • Profiles grant access to Objects and Fields
  • Permission Sets grant access to Objects and Fields

The Context Graph maps your org's structure and every link between its parts.

How changes reach Salesforce

Clientell patches the proposed change and audits its impact against the graph. When Clientell prepares a deploy, deploy_guard checks it and refuses unsafe replace-not-merge payloads for Profiles, Permission Sets and Sharing Rules. Once you approve, your AI client runs the deploy through your own sf session, under your credentials and permissions. Duplicate-record merges get the same care: merge_duplicate_records verifies every record ID against the org and drafts a merge plan it can prove safe, so the merge is checked before anything is deleted. The merge then runs through your own sf session.

1 You ask in plain English “What uses Industry?” 2 Clientell traverses the graph follows every link 3 Answer with sources and its build time graph built 2h ago 4 Optional one-line live check runs via your sf CLI

  1. You ask in plain English “What uses Industry?”
  2. Clientell traverses the graph follows every link
  3. Answer with sources and its build time graph built 2h ago
  4. Optional one-line live check runs via your sf CLI

Illustrative example. Answers come from the graph, so they're fast and show exactly where they came from.

Always know how fresh an answer is.

Every graph answer carries its last_graph_build timestamp. Rebuild the Salesforce graph whenever you want with one call, and confirm any Flow, Apex or validation-rule answer against the live org in one command.

Call clientell_set_active_org with no arguments to rebuild the graph after you change metadata. Answers about Flows, Apex classes, validation rules and other components come with a ready-to-run sf command that checks whether they changed in the live org since the last build. Connectors read the source system at question time, so their answers are current by design. Live Salesforce record lookups run when you ask, through Clientell’s auth service on your own Salesforce connection and permissions. The records pass through to your client and are not stored.

built 09:00 Graph built from your org's metadata answer · built 09:00 Every answer stamped with its build time compared with live org Live check before acting one command, against your org built 14:30 Rebuild on demand whenever you want rebuild: a fresh build time

Always know how fresh an answer is

  1. Graph built from your org's metadatabuilt 09:00
  2. Every answer stamped with its build timeanswer · built 09:00
  3. Live check before acting one command, against your orgcompared with live org
  4. Rebuild on demand whenever you wantbuilt 14:30 rebuild: a fresh build time, back to the start

Illustrative example with sample times. Every answer carries its build time, and one command checks it against your live org.

What this means in practice

Just added a field? Check the answer’s last_graph_build time. If the field is newer, rebuild and ask again, or run the live check that came with the answer before you act on it.

Your workspace is isolated. Your CLI stays yours.

Check who can query the graph, how writes are approved, and which credentials Clientell stores before connecting a production org.

Your workspace everyone in it sees the same map AK JL MR SP one shared org map Another workspace its own org map Another workspace its own org map sealed

Your workspace

  • AK
  • JL
  • MR
  • SP

everyone sees the same map

One shared org map one map for the whole workspace

nothing crosses

Another workspace its own org map

Another workspace its own org map

Each workspace is sealed off from every other. Inside one, everyone shares the same org map, so you decide who's in the workspace.

Graph scopes and isolation

Private, org and shared graph scopes use separate destinations. Workspace isolation prevents access across workspaces. Within a workspace, everyone sees the same org map, so you decide who is in the workspace. Graph queries do not apply each person’s individual Salesforce record-level or field-level permissions. Add the people who should share that view of the org.

How to read that

A teammate can ask about the structure of a field in the shared graph even if Salesforce would hide that field from them. Workspace membership is your control point, so grant it the way you would grant access to org metadata.

Write actions

Slack, Jira and GitHub can take actions: send a message, comment, or move an issue. These actions run through your AI client’s own tool-approval controls, so you set the confirmation policy there. Salesforce deploys take a different path: Clientell patches and audits the change, refuses unsafe replace-not-merge payloads it is asked to prepare, and your AI client uses your own sf session to deploy after you approve.

Credential storage

Stored credentials use AES-256-GCM encryption with a fresh nonce on each write. The Salesforce connection you authorise is stored this way and serves your live reads only for you, never for a teammate. Your Salesforce CLI session, which runs deploys, remains on your machine and is never visible to Clientell.

Use the MCP client you work in.

Clientell exposes tools and instructions over Streamable HTTP MCP with bearer auth. It is built and verified end to end on Claude Code, and works with any Streamable HTTP MCP client, including Cursor, VS Code, ChatGPT and Gemini.

VerifiedClaude Code

Built and verified end to end against this server. Follow the setup guide for the exact Claude Code commands.

CompatibleChatGPT, Copilot, Cursor, Gemini, VSCode, LibreChat, OpenCode, Windsurf

These clients speak the same Streamable HTTP MCP. Register the server with each client’s own add-server syntax; the setup guide has config snippets for the common ones.

This is not an allowlist. Any client supporting Streamable HTTP MCP with bearer auth can register the server. Claude Code is the client Clientell builds and verifies against end to end.

Connect Salesforce and ask your first question.

Authorize Salesforce, build your first Context Graph, then register Clientell in your MCP client. The worked commands below are for Claude Code.

1 Connect Salesforce sign in to your org 2 Build the graph maps your metadata 3 Add to your AI client Claude Code, Cursor, VS Code 4 Ask your first question “What uses Industry?”

  1. Connect Salesforce sign in to your org
  2. Build the graph maps your metadata
  3. Add to your AI client Claude Code, Cursor, VS Code
  4. Ask your first question “What uses Industry?”

From connection to first answer in four steps.

Before you start

Claude Code, installed and signed in

claude --version

Expect: a version string.

If missing: install it from Anthropic’s quickstart. We do not host our own installer.

The Salesforce CLI

sf --version

Expect: a line starting @salesforce/cli/.

If missing: install it from Salesforce. sf is not needed to register the hosted server or ask graph questions, and live record lookups go through your Clientell Salesforce connection instead. Keep it authenticated for live checks and approved Salesforce deploys, which run through your own CLI session.

An org you are authenticated to

sf org list

Expect: at least one org, not marked (expired).

If missing or expired: run sf org login web. An expired session still appears in the list and still fails at query time.

Check 4

A Clientell workspace

Where: the MCP setup page. Sign in, authorize Salesforce, wait for the first index, and copy the access token for Stage 3.

Note: the token is a bearer credential scoped to your Clientell workspace. It is not a Salesforce credential and cannot be used to reach Salesforce.

Check 5

The Clientell AI managed package, installed in your org

Install: production org or sandbox. The install itself takes about two minutes.

Who: Installing a managed package is a Salesforce administrator action. If you are not an admin on the org you want to index, ask one to install it before the OAuth step. Do this early if you need another team’s approval.

If missing: Salesforce returns external_app_not_installed during OAuth. Install the package in the org you are connecting, then retry. See Troubleshooting.

Not on this list

Node.js is a Claude Code prerequisite, not a Clientell server prerequisite. The MCP server is hosted; no local server process is required.

Stage 1

Connect your systems

Sign in and authorize the systems you need through OAuth. Start with Salesforce: its metadata forms the graph. Every other connector you authorize adds live reads of the work around it.

Authorize only what you need. A connector you have not authorized exposes no tools. Slack, Jira and GitHub can also take actions, so check your client’s tool-approval settings, described in Security and isolation.

Stage 2

Let the first index build

The first build indexes your org’s structure before graph queries are available. Large orgs take longer than developer orgs. After that, rebuild on demand whenever you want.

After registering the server, ask for clientell_onboarding_status to check build progress. Check it if a known object is missing from a graph answer.

Stage 3

Register the server with your client

Replace <YOUR_TOKEN> with the token from your workspace, keep the word Bearer and the space after it, then paste the whole thing into your terminal.

claude mcp add-json clientell '{
  "type": "http",
  "url": "https://mcp.clientell.ai/mcp",
  "headers": { "Authorization": "Bearer <YOUR_TOKEN>" },
  "timeout": 180000
}' --scope user

What you should see Added HTTP MCP server clientell to user config

The entry is saved. Verify the connection next. Claude Code does not test the URL or token when saving this entry. A wrong hostname or expired token fails on connection. Verify it worked is where you find out.

Line by line, hover or tab through to highlight each piece above

claude mcp add-json

Claude Code’s own command for registering an MCP server from a JSON block. Nothing of ours runs here, you are editing Claude Code’s configuration.

clientell

The name you will see in /mcp and in tool names. It is yours to pick; we use clientell throughout this page, and every other command here assumes you did too.

'{ … }'

The server entry, in single quotes so your shell passes it through untouched. Four keys: the first three are required, and timeout has a default, so it is recommended rather than mandatory.

"type": "http"

Says this is a remote server reached over HTTP. Leave it out and Claude Code reads the entry as a local command to run, finds none, and skips the server silently, it will not appear in claude mcp list at all.

"url": ".../mcp"

The single endpoint the server answers on. The /mcp at the end is part of the address, not decoration. Drop it and you get a “not found” error that reports only the hostname, which makes the cause hard to see.

"headers"

Your access token, sent on every request. Claude Code does not trim it, a stray space or newline from copying is sent as part of the token and the server rejects it.

"timeout": 180000

Three minutes, in milliseconds, as the ceiling for a single tool call. The default cuts a request off after 60 seconds, and a first query against a cold org graph can take longer than that. Values below 1000 are ignored entirely.

--scope user

Makes the server available in every project. Without it Claude Code uses its default scope, which binds the server to whichever directory you happened to be in, start Claude anywhere else and you will be told no MCP servers are configured. Scope is fixed when you add the server; changing it means removing and re-adding.

Prefer flags to JSON?

Same server, flag by flag. This form is easier to read, but it has no --timeout flag, so it cannot set the timeout, you have to add that afterwards by hand.

claude mcp add --transport http clientell https://mcp.clientell.ai/mcp \
  --header "Authorization: Bearer <YOUR_TOKEN>" \
  --scope user

Then open ~/.claude.json, find the clientell entry under the top-level mcpServers, and add "timeout": 180000 to it. If you would rather not hand-edit that file, use the JSON form above, that is why it is the primary path.

Other clients

Register the same hosted endpoint in your client’s config. Any Streamable HTTP MCP client works; these snippets cover the common ones, and the worked Claude Code path above is the one Clientell verifies end to end. See Supported clients, and check your client’s current documentation if its config format has changed.

Claude DesktopCompatible · not verified by us

Config ~/Library/Application Support/Claude/claude_desktop_config.json

{
  "mcpServers": {
    "clientell": {
      "type": "http",
      "url": "https://mcp.clientell.ai/mcp",
      "headers": { "Authorization": "Bearer <YOUR_TOKEN>" }
    }
  }
}

Restart Claude Desktop after editing. It reads this file only at launch.

Check Claude Desktop’s current custom-connector syntax if this block does not load.

CodexCompatible · not verified by us

Config ~/.codex/config.toml

[mcp_servers.clientell]
url = "https://mcp.clientell.ai/mcp"
http_headers = { Authorization = "Bearer <YOUR_TOKEN>" }

Codex reads remote MCP servers from its TOML config. Check its own documentation for the key names on your version, they have moved between releases.

CursorCompatible · not verified by us

Config ~/.cursor/mcp.json

{
  "mcpServers": {
    "clientell": {
      "url": "https://mcp.clientell.ai/mcp",
      "headers": { "Authorization": "Bearer <YOUR_TOKEN>" }
    }
  }
}

A project-local .cursor/mcp.json works too, and scopes the server to that repository instead of your whole account.

VS CodeCompatible · not verified by us

Config .vscode/mcp.json

{
  "servers": {
    "clientell": {
      "type": "http",
      "url": "https://mcp.clientell.ai/mcp",
      "headers": { "Authorization": "Bearer <YOUR_TOKEN>" }
    }
  }
}

Tip: VS Code uses servers as the top-level key, not mcpServers. If the server does not show up, check that key first.

Confirm your client can reach the graph.

Check the connection before asking about your org. Registering saves the entry; the first connection tests the endpoint and token.

The fast check

Check Clientell alone for a quick status.

claude mcp get clientell

What you should see Status: ✔ connected Scope: User config (available in all your projects) Type: http URL: https://mcp.clientell.ai/mcp

If something is wrong, recent versions of Claude Code print an Issue: line with the HTTP status and the server’s own error text. That line is the most useful thing on this page when you are stuck, take it to Troubleshooting.

The full check

Check every configured MCP server. This can take 30 to 60 seconds, or longer if another server is unresponsive.

claude mcp list

What you should see clientell: https://mcp.clientell.ai/mcp (HTTP) - ✔ Connected

And when it is not working, the same line ends differently: clientell: https://mcp.clientell.ai/mcp (HTTP) - ✘ Failed to connect — <reason>

Every status this can report

✔ Connected

Ready to use.

! Connected · tools fetch failed

The connection opened but the tool list did not come back. Run claude mcp get clientell for the detail.

! Needs authentication

The server is reachable and wants a credential it did not get.

✘ Failed to connect

No usable response. A reason usually follows the dash.

✘ Connection error

The attempt threw. Claude Code appends no detail to this one.

⏸ Pending approval

A project-scoped server awaiting approval. You will not see this if you used --scope user.

cached · connects on first use

Not an error. Claude Code remembered the tool list from a previous session and will connect when you first ask something.

On older Windows consoles the marks render as √ and × instead of ✔ and ✘. Same meanings.

Inside a session

Start Claude Code and type /mcp. You will see clientell listed with its tools.

Reconnection behaviour worth knowing

A 5xx or a dropped connection is retried automatically with backoff, so transient failures often clear themselves. Authentication and not-found errors are never retried, those need a configuration change, so they fail instantly and stay failed.

Start with a field you need to change.

Ask your AI client a plain-language question about your org. It chooses the relevant tools and answers from the graph.

  • What writes to Opportunity.Amount?Find flows, Apex, validation rules and processes that touch this field before editing it.
  • What breaks if I delete Account.Custom_Segment__c?Check references and impacted components before removing the field.
  • Show me every flow on Case that fires after save.Compare after-save automation on one object.
  • Which profiles can edit Contact.Email?Inspect field access across profiles and permission sets. What that actually did

These questions read metadata names, identifiers and relationships, not customer records. If you proceed with a change, Clientell patches and audits it, and your AI client runs the approved deploy through your own sf session.

A first question against a cold graph can take a while. If it runs past about two minutes, Claude Code moves it to a background task and tells you so. Answers are sized to fit your AI client’s context, and a sized answer says so and reports the full count. Ask a narrower question or page through for more.

Choose the org before trusting the answer.

Working across production and sandboxes? Set the active org so dependency answers come from the index you intended.

Two checks keep org selection explicit:

  • If it was not told which org you are working in, it says so in its answer rather than picking one for you.
  • If the org you selected and the org your token belongs to resolve to different indexes, it refuses the request instead of choosing between them.

Set the org for the session with clientell_set_active_org. It happens in the conversation, not in a config file, you ask the client to switch orgs and it calls the tool. To see what you are authenticated to locally:

sf org list

Salesforce context, plus the work around it.

Salesforce provides the metadata map. Eleven more connectors read the work around it, live, at question time: Slack, Jira, GitHub, Gmail, Google Calendar, Google Drive, Notion, Microsoft Teams, SharePoint, Outlook Mail and Outlook Calendar. Each one reads as you, through your own grant.

Salesforce read Slack read + write Jira read + write GitHub read + write Gmail read Google Calendar read Google Drive read Notion read Microsoft Teams read SharePoint read Outlook Mail read Outlook Calendar read

At the centre

Salesforce read

Connected around it

  • Slack read + write
  • Jira read + write
  • GitHub read + write
  • Gmail read
  • Google Calendar read
  • Google Drive read
  • Notion read
  • Microsoft Teams read
  • SharePoint read
  • Outlook Mail read
  • Outlook Calendar read

Twelve connectors, all read live when you ask.

ConnectorAccessStatusWhat you can ask forNotes
SalesforceReadLiveThe org graph: objects, fields, flows, Apex, validation rules, profiles and permission sets, plus the references between them. Live record, Tooling API, describe and limits reads when you ask.The graph holds no record contents. Clientell patches and audits changes, deploy_guard refuses unsafe replace-not-merge payloads in the deploys it prepares, and your AI client deploys through your own sf session after you approve.
SlackRead + writeLiveChannel history, message search and channel lists, read live as you. Send a message or add a reaction.Writes run through your AI client's tool-approval controls, so you set the confirmation policy. See the note below the table.
JiraRead + writeLiveIssue lookup and search, by text or JQL, read live. Comment on an issue or move it to another workflow state.Writes run through your AI client's tool-approval controls.
GitHubRead + writeLiveSearch repos, issues and PRs, open one PR or issue, and list the PRs waiting on you. Comment on a PR or issue.Comments post through the Clientell GitHub App, so install it on the repo's org first. Writes run through your AI client's tool-approval controls.
GmailReadLiveSearch and open messages and drafts, read live.
Google CalendarReadLiveYour agenda, event search and single events, read live.
Google DriveReadLiveFile search, file metadata and file text, read live.
NotionReadLiveSearch, page content and database rows, read live.
Microsoft TeamsReadLiveMessage search, channel history and single messages, read live.
SharePointReadLiveFile search, file metadata and file text, read live.
Outlook MailReadLiveSearch and open messages and drafts, read live.
Outlook CalendarReadLiveYour agenda, event search and single events, read live.

Live

Available today. Reads the source system at question time, through your own grant, so answers are current by design.

Read

Reads the source system when you ask. Exposes no action that changes anything there.

Read + write

Also takes actions in the source system, such as posting a message or a comment. Your AI client’s tool-approval settings decide when it asks you first.

You set the confirmation policy for connector writes

Slack, Jira and GitHub can take actions: send a Slack message or reaction, comment on or transition a Jira issue, comment on a GitHub PR or issue. These actions run through your AI client’s own tool-approval controls, so you decide whether each one asks first (see Claude Code, Cursor, or your client’s docs).

For Salesforce deploys, Clientell patches and audits the change. After you approve, your AI client runs the deploy through your own sf session. When Clientell prepares the deploy, the deploy guard refuses unsafe replace-not-merge payloads for Profiles, Permission Sets and Sharing Rules.

Connector tools

  • list_connector_capabilitiesLists your connected providers, their status, and the actions and arguments use_connector accepts for each.
  • use_connectorRuns a live read or action on a connected provider through your own account. Salesforce, when listed, is read-only: query, describe and limits.

Call all twelve connectors directly over MCP from your client. No separate agent surface is required.

Find dependencies, plan changes, check impact.

These nine tools answer org questions, draft changes and surface context. The server patches and audits proposed changes; after approval your AI client deploys through your own sf session. The duplicate-record merge tool proves a merge is safe before anything is deleted. /mcp also lists the setup tools below and the active connector tools.

Salesforce work · 9 Setup · 11 01 Find dependencies what touches what, and why search_salesforce_metadata search_team_context find_person_in_salesforce_and_work 02 Check impact impact, audit and access reports generate_salesforce_org_report 03 Plan changes guidance, drafts, merge plans and reports get_salesforce_best_practices search_salesforce_docs build_or_fix_salesforce_flow merge_duplicate_records manage_salesforce_reports_dashboards 04 Connect and select orgs, integrations, index status clientell_onboarding_status clientell_connect_salesforce clientell_set_active_org clientell_add_integration 05 Account billing, plan, your data clientell_billing_status clientell_upgrade clientell_delete_my_data 06 Memory and playbooks saved context, identity links, playbooks clientell_remember clientell_confirm_person_link clientell_push_work_records run_clientell_playbook

Salesforce work · 9

01 · Find dependencies

  • search_salesforce_metadata
  • search_team_context
  • find_person_in_salesforce_and_work

02 · Check impact

  • generate_salesforce_org_report

03 · Plan changes

  • get_salesforce_best_practices
  • search_salesforce_docs
  • build_or_fix_salesforce_flow
  • merge_duplicate_records
  • manage_salesforce_reports_dashboards

Setup · 11

04 · Connect and select

  • clientell_onboarding_status
  • clientell_connect_salesforce
  • clientell_set_active_org
  • clientell_add_integration

05 · Account

  • clientell_billing_status
  • clientell_upgrade
  • clientell_delete_my_data

06 · Memory and playbooks

  • clientell_remember
  • clientell_confirm_person_link
  • clientell_push_work_records
  • run_clientell_playbook

The Salesforce and setup tools, grouped by the job they do. The two connector tools are listed under Connectors.

  • search_salesforce_metadataTrace objects, fields, flows, rules and permissions. See what depends on a component before you change it, with curated audit sections when needed.
  • get_salesforce_best_practicesGet vetted guidance before building a Flow, writing a validation rule or loading data.
  • build_or_fix_salesforce_flowDraft a Flow from a plain-language request or diagnose a runtime error and propose a fix. Clientell patches and audits the change; approved deploys run through your AI client's own sf session.
  • search_salesforce_docsFind the relevant Salesforce documentation and cite the source guide.
  • generate_salesforce_org_reportGenerate an impact, audit or access report you can inspect and share.
  • search_team_contextSearch your team's email, Slack, Jira, meetings and documents for the people and decisions behind a Salesforce change, plus the context saved with clientell_remember.
  • find_person_in_salesforce_and_workFind a person across Salesforce and your team's email, Slack and Jira context, and say with an explicit confidence whether the records are the same human. Only an exact email match links automatically; anything weaker comes back as a question for you.
  • merge_duplicate_recordsFind duplicate Accounts, Contacts or Leads, verify every record ID against the org and draft a merge plan it can prove safe before anything is deleted. The merge runs through your own sf session.
  • manage_salesforce_reports_dashboardsBuild, update, run or delete native Salesforce Reports and Dashboards, including joined reports. It checks each report against the report type's real columns and hands back the exact sf command. You run it. Plumbing

Use these /mcp tools to connect and select an org, add integrations, manage billing and memory, confirm identity links, run playbooks and delete workspace data.

  • clientell_onboarding_statusCheck connected systems and whether your workspace index has been built.
  • clientell_connect_salesforceConnects a Salesforce org from your terminal when none is connected yet. It returns a link you open in the browser, then a second call confirms the connection.
  • clientell_set_active_orgSets which Salesforce org the session is working against. See Picking the right org.
  • clientell_add_integrationConnects Slack, Gmail or Jira to your workspace. It returns an authorization link, then a second call confirms the connection.
  • clientell_billing_statusReports the billing state of your workspace.
  • clientell_upgradeStarts an MCP ($249/mo) or Platform ($500/mo) subscription through Stripe Checkout, or opens the billing portal if you already subscribe. Nothing is charged until you finish checkout.
  • clientell_delete_my_dataDeletes the data held for you. See Uninstall and data deletion.
  • clientell_rememberSave work context explicitly. Nothing is stored automatically from your activity.
  • clientell_confirm_person_linkRecords your answer when find_person_in_salesforce_and_work asks whether two records are the same person, so it is not asked again. A wrong link can be undone.
  • clientell_push_work_recordsDemo bridge, not a live sync: indexes Gmail, Jira or local SFDX project records your AI client has already read. Only index fields are accepted, never message bodies or file contents.
  • run_clientell_playbookRuns a named Clientell playbook, such as standup or plan_data_load, for clients that cannot show this server's MCP prompts.

Connect a person across work systems.

Link a Salesforce User, Slack member and Jira account when their identifiers share a signal. Use that association to follow related work across connected systems.

Salesforce User 005Hs00000A1bC2 Slack Member U04F2K9QZ Jira Account 5b10ac8d82e05b22 Email Address dana@acme.com DR one person Dana Reyes

Dana Reyes one person

linked to

  • Salesforce User 005Hs00000A1bC2
  • Slack Member U04F2K9QZ
  • Jira Account 5b10ac8d82e05b22
  • Email Address dana@acme.com

Clientell links the same person across the tools your team uses.

Use associations as context, not access control

Coverage depends on the signals each connected system exposes. Identities with no shared signal may remain separate. Associations are not complete or accuracy-verified for every person in every org.

Check identity in the source system before making an access decision. An association is context, not identity proof.

Keep the decisions worth carrying forward.

Record why you made a change, then find that context in a later conversation. You or the model must explicitly call clientell_remember to save an entry.

01 Remember a fact is saved 02 Correct new version, old one kept 03 Expire stops being used v1 · saved APAC leads go to Priya valid until 31 Dec 2026 v1 · kept in history APAC leads go to Priya v2 · current APAC leads go to Sam valid until 31 Dec 2026 v2 · expired APAC leads go to Sam passed 31 Dec 2026 no longer returned to the model

  1. 01 · Remember v1 · saved APAC leads go to Priya valid until 31 Dec 2026
  2. 02 · Correct v2 · current APAC leads go to Sam valid until 31 Dec 2026 v1 · kept in history APAC leads go to Priya
  3. 03 · Expire v2 · expired APAC leads go to Sam passed 31 Dec 2026. No longer returned to the model.

Memory keeps what you choose, keeps its history, and expires on schedule.

You control what is saved

Memory does not learn your workflow automatically or infer entries from your activity. Each write is explicit. Earlier versions remain inspectable, but versioning does not restore an earlier state or roll back a change.

Find the error. Take the next step.

Start by checking whether the endpoint responds. Then match the status or error below to a specific fix.

curl -I https://mcp.clientell.ai/mcp

How to read the response code 404 or 405 the server is up — MCP endpoints answer POST, not HEAD 401 or 403 the server is up, and it wants a valid token no response wrong URL, DNS, or something on your network

On Windows PowerShell, use curl.exe, plain curl is an alias for something else and takes different arguments.

✘ Failed to connect — HTTP 401 What it means

The token is missing, expired, or not one this server accepts.

Fix

The most common cause is invisible: a leading or trailing space on the pasted token. Claude Code notices and warns Leading or trailing whitespace in: headers.Authorization but it does not trim it, and sends the value exactly as written. Remove the server, re-copy the token carefully, and add it again.

Otherwise, get a fresh token from your workspace and re-add. A rejected token is final, Claude Code reports the connection as failed rather than falling back to a browser sign-in.

Claude Code warns about whitespace in headers.Authorization

Your token has a space, tab or newline at one end. This comes from copying out of a web page and it is one of the most common ways this install fails.

Remove and re-add the server with a clean paste. Claude Code names the field but never echoes the value, so you cannot correct it by reading the warning.

claude mcp remove clientell -s user

MCP endpoint not found when you select the server in /mcp What it means

The URL in your configuration does not point at the endpoint. The message reports only the hostname, never the path, which hides the actual cause.

Fix

Check that your URL ends in /mcp. The full address is https://mcp.clientell.ai/mcp. Dropping that suffix is the usual reason for this message.

! Connected · tools fetch failed What it means

The connection opened, but the request for the tool list did not come back. The server is reachable; something failed after that.

Fix

Run claude mcp get clientell and read the Issue: line, it carries the HTTP status and the server’s error text. Read that output and redact anything sensitive before you share it with anyone, here or elsewhere.

✘ Failed to connect — HTTP 421, or every single request fails identicallyOurs to fix What it means

The server rejected the request because of a hostname configuration issue on our side.

Fix

Contact us with the status code and endpoint hostname. We will fix the server configuration.

✘ Failed to connect — ConnectionRefused What it means

Nothing is listening at that address.

Fix

Check the hostname in your client configuration. If you host the server yourself, check that it is listening at the configured address.

You added the server, but claude mcp list does not show it What it means

The entry has a url but no "type", so Claude Code read it as a local command to run, found none, and skipped it without reporting anything.

Fix

Add "type": "http" to the entry, or remove the server and re-add it with the JSON command in Stage 3, which includes it.

No MCP servers configured in a project where you know you added it What it means

The server was added at the default scope, which binds it to the single directory you were in when you ran the command.

Fix

Remove it and add it again with --scope user. Scope is fixed when the server is added; re-running add without removing first will fail.

MCP server clientell already exists in user config, right after you removed it

The remove did not take. claude mcp get prints the scope as a sentence (“User config (available in all your projects)”), but remove -s only accepts the short form.

Pass the short form exactly:

claude mcp remove clientell -s user

Everything times out after about 60 seconds What it means

Claude Code's default per-request limit. A first query against a cold org graph can exceed it.

Fix

Set a per-server timeout, the JSON command in Stage 3 does this for you with "timeout": 180000. Values below 1000 are ignored, so a small number is the same as no number.

The answer looks short, or a count seems too low What it means

Answers are sized to fit your AI client's context. When the server sizes a result, it says so and reports the true row count alongside the rows it returned. Claude Code also trims very large tool output on its own, without a marker.

Fix

Ask a narrower question or page through for more. If the result says it was sized down, use the reported count, not the number of rows you can see.

A generated report ends mid-sentence What it means

The document is larger than the size that fits your client's context. The result carries a note naming how many characters were left out.

Fix

Re-run with a narrower scope, such as one object or one profile at a time. Share the report once it arrives complete, with its closing structure intact.

An answer is missing something you know exists in the org What it means

Most often the graph was last built before that component was created. Every graph answer carries its last_graph_build time, so you can compare.

Fix

Rebuild with clientell_set_active_org (no arguments) and ask again, or run the live check that came with the answer. Check clientell_onboarding_status if you are not sure whether the first build has finished. See Freshness.

The org index does not exist, or the request is refused because two orgs disagree What it means

Either no index has been built for that org yet, or the org you are working in and the org your token belongs to point at different indexes. In the second case the server refuses rather than picking one.

Fix

Both errors name what was looked for. Set the org explicitly with clientell_set_active_org, and see Picking the right org. If an index has never been built for that org, send us the error text.

A connector is authorised but its tools return nothing What it means

Connectors read the source system live, as you, so they return only what your own account in that system can see. Two likely causes: a query that matches nothing, or a grant that has expired.

Fix

Try the same search in the source system under your own account. If it finds results there, reconnect the connector from your workspace and ask again. See Connectors for what each one reads.

Connecting Salesforce fails with external_app_not_installed What it means

The Clientell AI managed package is not installed in the org you are connecting. Salesforce reports this as OAUTH_EC_APP_NOT_FOUND: the app being authorised does not exist in that org, so the consent screen has nothing to grant.

Fix

Install the package in the org you are connecting, production or sandbox then run the connection again. It takes about two minutes, and nothing you did earlier needs redoing.

Installing a managed package is an administrator action, so if you are not an admin on that org this is the step that needs someone else. It is the most common reason a first connection fails, which is why it is Check 5 in the prerequisites rather than only here.

Check which org you are connecting before you conclude the install failed. The package is installed per org, so a sandbox can be missing it while production has it, and the error looks identical either way.

Connecting Salesforce fails with oauth_session_mismatch What it means

For a terminal-initiated connection, the Clientell account signed in to your browser does not match the account that started the connect. The connection cannot continue under a different account.

Fix

Sign in to Clientell in this browser with the account your coding agent uses. Then ask your coding agent for a fresh connect link and open it in this same browser profile.

Signing in alone does not revive the previous attempt. The connect record is single-use, so you still need a new link from your terminal after correcting the account.

Connecting Salesforce fails with connect_expired What it means

The terminal-generated connect link has expired or was already used. Connect links are single-use, and a pending connection expires after 30 minutes.

Fix

Go back to your terminal and ask your coding agent to connect Salesforce again. Open the new link in this same browser and finish the Salesforce step without leaving it open too long.

Do not reuse the old link or start a separate connection from the browser. A fresh browser-only connection cannot complete the handshake your terminal is waiting for.

Connecting Salesforce fails with authorization_expired What it means

The Salesforce sign-in took too long. The connect link was opened in time, but the Salesforce authorisation step exceeded its ten-minute window.

Fix

Ask your coding agent for a fresh connect link. Have your Salesforce password and MFA device ready first, then complete the Salesforce sign-in within ten minutes without pausing.

Restart from the new terminal-generated link, not a separate browser-only connection. The previous attempt cannot be resumed after the authorisation window expires.

sf org list shows your org as expired, or sf commands start failing

Your Salesforce session lapsed. That session lives on your machine and we never see it, so we cannot refresh it for you.

sf org login web

claude plugin marketplace add returns a 404 What it means

Clientell registers as an HTTP MCP server, not a Claude plugin marketplace.

Fix

Use the setup on this page. It is the only supported path.

Disconnect the client. Delete the workspace data.

Remove the server entry to stop using it in Claude Code. Delete the data held for you separately, then revoke any connector authorizations you no longer need.

Remove the server

claude mcp remove clientell -s user

What this removes the clientell entry in Claude Code’s user configuration

This removes the client configuration, not your workspace data. Shell history and client logs may still contain the token pasted during setup. -s takes the matching scope: user, project or local.

Delete your data

Before removing the server, ask your client to call clientell_delete_my_data to delete the data held for you. Removing a client configuration does not delete its underlying workspace data.

Revoke the connections too

Deleting data does not revoke an OAuth authorisation. Revoke each connector from your workspace, or from the source system’s own connected-app settings, if you want the authorisation gone as well.

Quick answers before you connect.

Find the key details on record data, graph permissions, deployment, connectors and supported clients.

Does Clientell store our Salesforce record data?

No. The graph indexes names, identifiers, metadata and relationships, never record contents. When you ask for live records, Clientell’s auth service runs a read-only query on your own Salesforce connection, with your permissions, and passes the rows straight back to your client. They are never written to the graph.

Does the graph enforce each person's Salesforce permissions?

Workspace isolation prevents access across workspaces. Inside a workspace, everyone sees the same org map: graph queries do not apply each person’s individual Salesforce record-level or field-level permissions. That makes workspace membership your control point, so you decide who is in the workspace.

Can Clientell deploy a Salesforce change?

Yes, after you approve. Clientell patches and audits the change. When Clientell prepares a deploy, deploy_guard checks it and refuses unsafe replace-not-merge payloads for Profiles, Permission Sets and Sharing Rules. Your AI client then runs the deploy through your own authenticated sf session. Clientell never sees that session. For duplicate records, merge_duplicate_records verifies every record ID against the org and drafts a merge plan it can prove safe, so the merge is checked before anything is deleted. The merge then runs through your own sf session.

Who decides whether a Slack action asks me first?

You do. Slack actions, like Jira and GitHub actions, run through your AI client’s own tool-approval controls, so you set the confirmation policy there. Set it to ask before every write if that is what your team wants.

How current is the graph?

You always know. Every graph answer carries its last_graph_build timestamp, and one call rebuilds the graph whenever you want. Flow, Apex and validation-rule answers come with a ready-to-run live check, so you can confirm against the live org in one command before acting. Connectors read at question time, so their answers are current by design.

Which connectors work today?

Twelve, all read live when you ask: Salesforce, Slack, Jira, GitHub, Gmail, Google Calendar, Google Drive, Notion, Microsoft Teams, SharePoint, Outlook Mail and Outlook Calendar. Slack, Jira and GitHub can also take actions, such as posting a message or a comment.

Which MCP clients is this verified against?

Clientell is built and verified end to end on Claude Code. It works with any Streamable HTTP MCP client, including Cursor, VS Code, ChatGPT and Gemini, and the setup guide has config snippets for the common ones.

Are connectors available directly over MCP, or only inside your agent?

Directly over MCP. Your client calls all twelve connectors as ordinary MCP tools. There is no separate agent-only surface you have to go through.

What does the server remember between conversations?

Only what you or the model explicitly writes. Entries can be corrected, each write is kept as a version rather than overwriting the last, and entries carry a time-based expiry. Nothing is inferred from your activity and stored on its own.

How are stored credentials protected?

Stored credentials are encrypted using AES-256-GCM, with a fresh nonce for each storage write.

How much does Clientell MCP cost?

Clientell MCP is $249/month for 10 people on one production Salesforce org, then $25/month per extra person, with unlimited sandboxes. The Platform plan is $500/month for 3 people with deployments and weekly org audits. All plans include a 14-day free trial with no credit card required. See Pricing.

How do I remove it and delete my data?

Remove the server entry from your client, then call clientell_delete_my_data to delete the data held for you. These are separate actions. Revoke OAuth connections separately. Shell history or client logs may still contain the token pasted during setup. See Uninstall and data deletion.

Changes to this document.

Material changes to what this page claims. Wording fixes and typography are not listed.

  • 26 Sep 2026 Lists all twelve live connectors with their verified access levels. HubSpot is no longer listed. Explains graph freshness through last_graph_build and the live checks that come with Flow, Apex and validation-rule answers.
  • 25 Sep 2026 Clarifies the approved Salesforce deploy workflow, deploy guard and duplicate-merge boundary. Setup includes the managed-package prerequisite and the external_app_not_installed recovery path.
  • First published with setup steps, connector status, graph security, identity resolution and memory guidance.

Connector status reflects what is available today. All twelve listed connectors are live.