From ddcde503c623e2ef82a8e1e0c4e9d2facca97069 Mon Sep 17 00:00:00 2001 From: minu Date: Wed, 7 Oct 2026 17:36:24 -0700 Subject: [PATCH] feat(third_party): add Salesforce Headless 360 plugin New salesforce-headless-360 plugin for Salesforce's Headless 360 (Beta) hosted MCP server. Admin-set required server URL, Consumer Key, and Consumer Secret; members only sign in. The existing salesforce plugin is unchanged. --- .cursor-plugin/marketplace.json | 5 + README.md | 1 + .../.cursor-plugin/plugin.json | 56 ++++++++ .../salesforce-headless-360/CHANGELOG.md | 10 ++ third_party/salesforce-headless-360/LICENSE | 21 +++ third_party/salesforce-headless-360/README.md | 123 ++++++++++++++++++ .../salesforce-headless-360/assets/logo.svg | 7 + third_party/salesforce-headless-360/mcp.json | 13 ++ 8 files changed, 236 insertions(+) create mode 100644 third_party/salesforce-headless-360/.cursor-plugin/plugin.json create mode 100644 third_party/salesforce-headless-360/CHANGELOG.md create mode 100644 third_party/salesforce-headless-360/LICENSE create mode 100644 third_party/salesforce-headless-360/README.md create mode 100644 third_party/salesforce-headless-360/assets/logo.svg create mode 100644 third_party/salesforce-headless-360/mcp.json diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json index 1ecaffa74..a93fec22e 100644 --- a/.cursor-plugin/marketplace.json +++ b/.cursor-plugin/marketplace.json @@ -133,6 +133,11 @@ "source": "third_party/salesforce", "description": "Query, create, and update records in your org." }, + { + "name": "salesforce-headless-360", + "source": "third_party/salesforce-headless-360", + "description": "Manage records, users, and org setup across Salesforce." + }, { "name": "playwright", "source": "third_party/playwright", diff --git a/README.md b/README.md index ce4be85ff..3ce5fb51a 100644 --- a/README.md +++ b/README.md @@ -31,6 +31,7 @@ Official Cursor plugins for popular developer tools, frameworks, and SaaS produc | `google-slides` | [Google Slides](third_party/google-slides/) | Cursor | Productivity | Create, edit, and render presentations. | | `gong` | [Gong](third_party/gong/) | Cursor | Integrations | Pull account summaries, deal insights, and call briefs. | | `salesforce` | [Salesforce](third_party/salesforce/) | Cursor | Integrations | Query, create, and update records in your org. | +| `salesforce-headless-360` | [Salesforce (Headless 360, Beta)](third_party/salesforce-headless-360/) | Cursor | Integrations | Manage records, users, and org setup across Salesforce. | | `playwright` | [Playwright](third_party/playwright/) | Cursor | Integrations | Navigate, click, screenshot, and test in a real browser. | | `github` | [GitHub](third_party/github/) | Cursor | Integrations | Manage repos, issues, pull requests, and Actions. | | `ashby` | [Ashby](third_party/ashby/) | Cursor | Integrations | Search candidates, prep interviews, and manage pipeline tasks. | diff --git a/third_party/salesforce-headless-360/.cursor-plugin/plugin.json b/third_party/salesforce-headless-360/.cursor-plugin/plugin.json new file mode 100644 index 000000000..02528c6fd --- /dev/null +++ b/third_party/salesforce-headless-360/.cursor-plugin/plugin.json @@ -0,0 +1,56 @@ +{ + "name": "salesforce-headless-360", + "displayName": "Salesforce (Headless 360, Beta)", + "version": "1.0.0", + "description": "Manage records, users, and org setup across Salesforce.", + "author": { + "name": "Cursor", + "email": "plugins@cursor.com" + }, + "homepage": "https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/headless-360-mcp.html", + "repository": "https://github.com/cursor/plugins", + "license": "MIT", + "logo": "assets/logo.svg", + "keywords": [ + "salesforce", + "crm", + "mcp", + "sales", + "headless-360", + "admin" + ], + "category": "integrations", + "tags": [ + "mcp", + "crm", + "sales" + ], + "variables": { + "type": "object", + "properties": { + "SALESFORCE_MCP_URL": { + "type": "string", + "title": "Salesforce MCP server URL (set by your Salesforce admin)", + "description": "Headless 360 server URL from Salesforce Setup → MCP Servers. Production and Developer orgs: https://api.salesforce.com/platform/mcp/v1/platform/headless-360. Sandbox and scratch orgs: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/headless-360.", + "default": "https://api.salesforce.com/platform/mcp/v1/platform/headless-360" + }, + "CLIENT_ID": { + "type": "string", + "title": "Salesforce Consumer Key (set by your Salesforce admin)", + "description": "Your Salesforce admin creates the External Client App and enters its Consumer Key here once for the whole team (Setup → External Client App Manager → your app → Settings → Consumer Key and Secret). Team members don't need this value; they only sign in to Salesforce." + }, + "CLIENT_SECRET": { + "type": "string", + "title": "Salesforce Consumer Secret (set by your Salesforce admin)", + "description": "Consumer Secret from the same External Client App, entered once by your Salesforce admin for the whole team. Team members don't need this value.", + "writeOnly": true + } + }, + "required": [ + "SALESFORCE_MCP_URL", + "CLIENT_ID", + "CLIENT_SECRET" + ] + }, + "mcpServers": "./mcp.json" +} diff --git a/third_party/salesforce-headless-360/CHANGELOG.md b/third_party/salesforce-headless-360/CHANGELOG.md new file mode 100644 index 000000000..1c079180d --- /dev/null +++ b/third_party/salesforce-headless-360/CHANGELOG.md @@ -0,0 +1,10 @@ +# Changelog + +All notable changes to this plugin will be documented here. + +## 1.0.0 — initial release + +- Added the `salesforce-headless-360` MCP server for Salesforce's Headless 360 (Beta) hosted MCP server. +- Declared required `SALESFORCE_MCP_URL`, `CLIENT_ID`, and `CLIENT_SECRET` plugin variables, labeled as values a Salesforce admin sets once for the team. The server URL defaults to the production Headless 360 URL. +- Pinned OAuth scopes to `mcp_api` and `refresh_token`. +- Logo: the same Salesforce mark as the `salesforce` plugin. diff --git a/third_party/salesforce-headless-360/LICENSE b/third_party/salesforce-headless-360/LICENSE new file mode 100644 index 000000000..ca2bba771 --- /dev/null +++ b/third_party/salesforce-headless-360/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 Cursor + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/third_party/salesforce-headless-360/README.md b/third_party/salesforce-headless-360/README.md new file mode 100644 index 000000000..87f8179e3 --- /dev/null +++ b/third_party/salesforce-headless-360/README.md @@ -0,0 +1,123 @@ +# Salesforce (Headless 360, Beta) + +Cursor plugin that connects agents to Salesforce's [Headless 360 MCP server](https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/headless-360-mcp.html) (Beta), part of [Salesforce Hosted MCP](https://developer.salesforce.com/docs/platform/hosted-mcp-servers/). + +Headless 360 gives agents access across Salesforce through four tools backed by a growing library of Salesforce operations. Agents can query, create, and update records; manage users, permission sets, and permission set licenses; work with Apex triggers, platform events, and Change Data Capture; set up named credentials; and manage Commerce Cloud orders. Every call runs as the signed-in user, with that user's object permissions, field-level security, and sharing rules. + +This plugin is separate from the [`salesforce`](../salesforce/) plugin, which connects to the SObject and custom Hosted MCP servers. Both can be installed at the same time. + +## Who does what + +| Role | What they do | +|:-----|:-------------| +| **Salesforce admin** | Creates the External Client App, activates Headless 360, and enters the **server URL**, **Consumer Key**, and **Consumer Secret** once in the team's plugin settings. | +| **Everyone else on the team** | Installs the plugin and signs in to Salesforce. Members don't need the Consumer Key or Secret and can't get them from their own Salesforce accounts. | + +## Install + +1. Open **Cursor Settings → Plugins**. +2. Search for **Salesforce (Headless 360, Beta)**. +3. Click **Install**. If your admin has configured the plugin for your team, complete the Salesforce sign-in prompt. If you're asked for a server URL, Consumer Key, and Consumer Secret, ask your Salesforce admin to configure the plugin for the team first. + +## Tools + +| Tool | What it does | +|:-----|:-------------| +| `discover` | Finds Salesforce operations that match a request. | +| `describe` | Returns an operation's parameters, dependencies, and steps. | +| `dispatch` | Runs an operation. It can change data and org configuration. | +| `dispatch_readonly` | Runs read-only operations. It never changes data or configuration. | + +## MCP + +```json +{ + "mcpServers": { + "salesforce-headless-360": { + "type": "http", + "url": "${SALESFORCE_MCP_URL}", + "auth": { + "CLIENT_ID": "${CLIENT_ID}", + "CLIENT_SECRET": "${CLIENT_SECRET}", + "scopes": ["mcp_api", "refresh_token"] + } + } + } +} +``` + +## Admin setup + +### 1. Activate Headless 360 + +Headless 360 needs API version 67.0 or later. From Setup, enter **MCP Servers** in Quick Find, select **MCP Servers**, find **headless-360**, and click **Activate**. + +### 2. Create the External Client App + +From Setup, go to **External Client App Manager → New External Client App**, fill in the basics, then expand **API (Enable OAuth Settings)** and check **Enable OAuth**. Connected Apps are not supported. + +Add every callback URL Cursor and Grok Bot use: + +| Surface | Callback URL | +|:--------|:-------------| +| Cursor desktop | `http://localhost:8787/callback` | +| Cursor desktop (IPv4 loopback) | `http://127.0.0.1:8787/callback` | +| Web and Cloud Agents | `https://www.cursor.com/agents/mcp/oauth/callback` | +| Older Cursor desktop builds | `cursor://anysphere.cursor-mcp/oauth/callback` | +| Grok Bot | `grokbot://mcp/oauth/callback` | +| Grok Bot (browser handoff) | `https://www.cursor.com/bot/mcp/oauth/callback` | + +Under **OAuth Scopes**, select exactly these two and nothing broader: + +- **Access Salesforce hosted MCP servers** (`mcp_api`) +- **Perform requests at any time** (`refresh_token`, `offline_access`) + +The second one is easy to miss because the picker labels scopes by description rather than by value. Without it, members have to sign in again every time their access token expires. Do not add **Full access** (`full`). + +Under **Security**: + +- Select **Issue JSON Web Token (JWT)-based access tokens for named users**. Without it, Salesforce issues opaque tokens and every tool call fails with `JWT Token is required`. +- Keep **Require Proof Key for Code Exchange (PKCE)** and **Require Secret for Web Server Flow** on. +- Do not enable the **JWT Bearer Flow**, which is a different feature and needs a certificate. + +Copy the **Consumer Key** and **Consumer Secret** from **Settings → Consumer Key and Secret**. + +A new External Client App can take up to 30 minutes to propagate. Until it does, sign-in fails with `invalid_client_id`; wait rather than recreating the app. + +### 3. Configure the plugin for your team + +In **Dashboard → Plugins → Configure**, set these on your team marketplace: + +| Setting | Value | +|:--------|:------| +| **Salesforce MCP server URL** | `https://api.salesforce.com/platform/mcp/v1/platform/headless-360` for production and Developer orgs, or `https://api.salesforce.com/platform/mcp/v1/sandbox/platform/headless-360` for sandbox and scratch orgs. | +| **Salesforce Consumer Key** | The Consumer Key from step 2. | +| **Salesforce Consumer Secret** | The Consumer Secret from step 2. | + +Members then skip setup and go straight to the Salesforce sign-in. The secret is masked in the settings UI. Cursor still delivers it to each member's client, because desktop clients run the sign-in themselves. + +## Approvals for changes + +`dispatch` can change org configuration or data, for example creating or deactivating users, assigning permission sets, or deploying Apex. Configure your client to ask for approval before it runs `dispatch`, and let `dispatch_readonly` run without approval. Try configuration changes in a sandbox or Developer org before production. + +## Troubleshooting + +| Symptom | Cause | +|:--------|:------| +| A member is asked for a server URL, Consumer Key, and Consumer Secret | Your Salesforce admin has not configured the plugin for the team yet. | +| `invalid_client_id` | The External Client App has not finished propagating. Wait up to 30 minutes. | +| `invalid_client` or `invalid client credentials` | The Consumer Secret doesn't match the Consumer Key. Copy both again from the same app. | +| `redirect_uri_mismatch` | The app is missing the callback URL for the surface you signed in from. Add all callback URLs above. | +| `invalid_scope` | The app is missing **Access Salesforce hosted MCP servers** or **Perform requests at any time**. | +| `JWT Token is required` or `Invalid token` after a successful login | **Issue JSON Web Token (JWT)-based access tokens for named users** is not enabled. | +| Sign-in succeeds but the server 404s | Headless 360 is not activated in Setup, or the URL's org type (production or sandbox) doesn't match the org you signed in to. | + +## Docs + +- Headless 360 MCP server: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/headless-360-mcp.html +- Create an External Client App: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/create-external-client-app.html +- Configure Cursor: https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/cursor.html + +## License + +MIT diff --git a/third_party/salesforce-headless-360/assets/logo.svg b/third_party/salesforce-headless-360/assets/logo.svg new file mode 100644 index 000000000..7259a1e05 --- /dev/null +++ b/third_party/salesforce-headless-360/assets/logo.svg @@ -0,0 +1,7 @@ + + Salesforce + + + + + diff --git a/third_party/salesforce-headless-360/mcp.json b/third_party/salesforce-headless-360/mcp.json new file mode 100644 index 000000000..8f6792a0e --- /dev/null +++ b/third_party/salesforce-headless-360/mcp.json @@ -0,0 +1,13 @@ +{ + "mcpServers": { + "salesforce-headless-360": { + "type": "http", + "url": "${SALESFORCE_MCP_URL}", + "auth": { + "CLIENT_ID": "${CLIENT_ID}", + "CLIENT_SECRET": "${CLIENT_SECRET}", + "scopes": ["mcp_api", "refresh_token"] + } + } + } +}