Salesforce Agent Integration Protocols

Last Updated: June 30, 2026

This documentation outlines the protocols governing third-party artificial intelligence ("Agents") accessing Salesforce APIs. These protocols are mandatory for all automated use of SFDC APIs, as defined in the Salesforce APIs License and Terms of Service, by agents and are incorporated into those Terms by reference.

Services Covered

This documentation applies to the SFDC APIs. The SFDC APIs, as updated from time to time, are published by SFDC and made available:

  • at developer.salesforce.com and/or
  • in the SFDC API Library here (the "Library").

Agent Identity And Authentication

To ensure security and observability, Agents must maintain clear and distinct identities.

  • No Masking: Developers must not misrepresent or mask the identity of the API client, Connected App, or External Client App. When a Developer makes Commercial Use of the Salesforce APIs, they should interface through Connected Apps or External Client Apps created by the Developer.
  • No Agent Chaining: The use of Agent-to-Agent chains to mask the identity of an originating agent accessing the SFDC APIs is strictly prohibited.
  • Credential Integrity: Agents should use valid credentials assigned specifically to them and must not share or sell access credentials.

Data Minimization

Agents must adhere to least-privilege principles, limiting data access and retention to the minimum necessary for the Agent's specific functionality.

Operational Limits and System Integrity

Agents must operate within defined consumption limits to prevent system instability.

  • Rate Limits: Agents must not circumvent SFDC rate limits or engage in excessive or abusive behavior, as defined by SFDC.
  • Agent-specific APIs: Where Salesforce provides generally-available agentic-specific APIs, such as Model Context Protocol (MCP) or the Agentforce APIs and SDKs, Agents should use these specific APIs instead of more general APIs or non-Salesforce solutions.
  • Vulnerability Testing: Agents are prohibited from testing the vulnerability of SFDC systems or networks unless expressly authorized by SFDC.

Acceptable Use

Use of Agents in conjunction with Salesforce Services must strictly comply with the Artificial Intelligence Acceptable Use Policy.