The quickest way to connect Claude to Salesforce is to create an external client app, copy its consumer key and secret into a local model context protocol (MCP) server's config file, and point Claude at it. The credential then sits in that file until someone rotates it, and every request arrives as that one identity, hence the Salesforce log can't show who asked what.
The alternative is a token issued to a user rather than to the application. It carries that person's permissions, so Claude reaches no more than they could open themselves, and the grant can be revoked for that user alone. The work is in scoping that token correctly and proving that Claude can't reach past the person asking.
What "raw API access" means in Salesforce, and why it's a governance risk
Raw API access means an outside tool holds a Salesforce credential of its own, usually a consumer key and secret, and calls the REST or SOAP API directly. It identifies the application rather than the user making the request and stays valid until someone rotates or revokes it.
A key in a config file is hard to revoke cleanly, so a single leak reaches everything that tool can touch. And because Salesforce grants permissions to the application, the tool can fetch anything that stored identity can reach.
With open authorization (OAuth), no credential reaches the outside app at all. The person signs in, Salesforce issues a token tied to their consent, and that token can be scoped and revoked on its own. Salesforce restricted the creation of new connected apps in its Spring '26 release and recommends external client apps in their place. For MCP clients, external client apps are the only option it supports.
The managed AI gateway: a safer way to connect Claude to Salesforce
MCP is an open standard created by Anthropic, now held by the Agentic AI Foundation under the Linux Foundation. It defines one way for AI applications to discover and call outside tools and data.
Access control runs on OAuth 2.1. The MCP server acts as the resource server, a separate authorization server handles sign in and issues the token, and the client requests access on behalf of the person using it. The June 2025 revision formalized that split and added Resource Indicators (RFC 8707), tying a token to the one service it was issued for. The November 2025 revision made proof key for code exchange (PKCE) mandatory for every client.
MCP standardizes how authentication works, but it does not define every security control around the connection. The teams operating the host, client, and server are still responsible for scoping access, logging activity, and protecting the endpoint. A managed AI gateway can handle these controls centrally instead.
CData Connect AI has an Anthropic verified connector in Claude's directory, and it sits between Claude and the Salesforce API as one remote MCP endpoint. It uses identity passthrough, where the request carries the end user's own identity to the source, so access is evaluated per user rather than through a shared account, over OAuth or security assertion markup language (SAML).
How to connect Claude to Salesforce through CData Connect AI
Connect AI works across claude.ai, Claude Desktop, Claude Code, and Cowork. The Salesforce work happens on the Connect AI side, where you decide what the connector can reach. On Team and Enterprise plans, an Owner adds it for the organization and members then connects with their own account, which keeps the decision with an admin.
Configure the Salesforce connector and connect to your remote MCP endpoint
In Connect AI, open Sources, click Add Connection, and pick Salesforce. Click Sign in and complete the OAuth login. Connect AI holds the token it gets back and uses it for requests made on that person's behalf.
Decide what the connection should expose before anyone uses it, since connection permissions are what keep Claude to the objects you approve. CData's Salesforce to Claude walkthrough shows this process in detail.
Connect Claude Desktop or Claude chat and validate OAuth and SAML passthrough
In Claude, open Settings, select Connectors, then click Browse connectors and search for CData Connect AI. Click the listing, click Connect, and sign in to your Connect AI account to grant access.
Validate the passthrough before anyone relies on it. Sign in as a user with limited Salesforce permissions and ask Claude for something they shouldn't see. Nothing should come back, because the request carries that user's token. If restricted data appears, check the OAuth scopes and the connection identity. Run the test in a sandbox, as our guide to secure Salesforce and Claude integration recommends.
Governing AI access: least privilege controls, audit trails, and workspace scoping
Least privilege here means giving the connector only the OAuth scopes and object permissions the job needs. You assign scopes to the external client app when you build it, and Salesforce issues them with the token, so scoping the app scopes Claude.
Salesforce permissions continue to apply when data is accessed through MCP. Field level security, sharing rules, and user permissions determine what each user can see, so a sales rep and an executive can access the same connection while receiving only the data their Salesforce permissions allow.
Connect AI adds another layer of access control on top of the source system. Permissions are set per user on each connection, with separate SELECT, INSERT, UPDATE, DELETE, and EXECUTE rights, and a new connection is admin only until someone grants access. Workspaces in Connect AI provide broader access management for teams. A workspace can contain the connections a particular team needs, and access is granted to the appropriate users as a group. Learn more about how Connect AI constrains agent access.
Claude adds its own controls on top of this. On Team and Enterprise plans, an Owner can set the tool policy for the entire organization. For example, the policy can allow users to fetch data while preventing actions that change it, without allowing individual members to override the restriction. On Enterprise, custom roles can narrow access further for individual connectors or tools.
Governance control | Where it's enforced | What it protects against |
OAuth scope restriction | External client app in Salesforce. | Objects beyond the approved set. |
Identity passthrough | Connect AI endpoint. | Service accounts hiding who asked. |
Per user connection permissions | Connect AI connection. | Write access for users who should only read. |
Field level security and sharing rules | Salesforce permission model. | Records outside a user's access. |
Org-wide tool policy | Claude organization settings. | Write actions nobody approved. |
Central request logging | Connect AI endpoint. | Audit gaps in a compliance review. |
What you can do with live Salesforce data in Claude
Claude can request Salesforce records as they are needed in the conversation, so responses reflect the data currently available in the org without relying on exports or manually copied data.
A common example is pipeline analysis. The sales team can ask what is currently in commit for the quarter, then dig into how that pipeline has changed since the previous week.
Claude can also pull the open deals over a set amount and sum up what's blocking each one or return the top accounts by revenue with their open cases. None of it needs Salesforce object query language (SOQL) or a saved report. The same pattern works for other systems, as CData's MySQL and Claude guide and Shopify walkthrough show.
Read access and write access are worth deciding separately. MCP handles both, so Connect AI can expose approved writes where Claude updates a record or kicks off a workflow. If you only want answers, scope the connection to read access only.
Say "yes" to connecting Claude with CData Connect AI
Security reviewers typically look at credential storage, permission enforcement, and audit logging. CData Connect AI provides these details, so teams can document how access is secured and how activity can be traced. CData has also completed independent SOC 2 Type II and ISO/IEC 27001:2022 audits, which are commonly requested as part of the security review process.
The same approach can also be used when other business systems need to be connected. Connect AI supports hundreds of data sources through the same MCP endpoint, so teams can apply a consistent access model across systems. Set up your Salesforce to Claude connection through CData Connect AI. Start a free trial to connect your own data.
Frequently asked questions
Can Claude connect to Salesforce without using raw API keys or credentials?
Yes. Through a managed MCP endpoint, Claude gets a delegated OAuth token scoped to the signed-in user and never stores a consumer key.
What is an MCP server, and why does it matter to connect Claude to Salesforce?
It exposes a system's data and actions as standard tools an AI app can call, so Claude reaches Salesforce records through that interface, with its own sign in and scoping.
How does Claude authenticate with Salesforce if it isn't using a raw API key?
Through OAuth. The person signs in, Salesforce issues a token tied to that consent, and requests from Claude carry it.
What's the difference between connecting Claude to Salesforce directly versus using a governed MCP layer?
A direct connection leaves sign in, scoping, and logging for you to build per source. A governed layer handles all three in one place and serves other systems from the same endpoint.
What can Claude do once it's connected to Salesforce data?
Answer questions from live records: pipeline summaries, opportunity reviews, and account health checks. With write access granted deliberately, it can update records or start approved workflows.
Does connecting Claude to Salesforce expose my CRM data or create security risks?
Access stays limited to what the signed-in user can already see, since field level security and sharing rules still apply. Watch for over broad OAuth scopes and un-scoped write access.
How is this different from building a custom Salesforce integration or using an iPaaS like MuleSoft?
A custom integration or iPaaS pipeline moves data on a schedule and takes engineering time per source. A managed MCP layer leaves the data in Salesforce and fetches it when asked, so there are no copies to maintain.