
The TL;DR
Salesforce’s Hosted MCP Servers reached general availability in April 2026, and the timeline behind that release tells a different story than most coverage suggests.
-
• Two Milestones, Ten Months Apart
The MCP client Agentforce announced in June 2025 and the hosted servers that reached GA in April 2026 are separate events, not one announcement.
-
• Salesforce Joins a Pattern Already in Motion
Microsoft and ServiceNow built native MCP support into their own platforms first, which changes what Salesforce’s move actually signals.
-
• An Open Protocol Doesn’t Erase Lock-In
Each vendor’s hosted server still runs inside that vendor’s own governance model, so adopting MCP doesn’t remove the work of managing multiple tool integrations.
A claim is now circulating that Salesforce anchored Agentforce 3 around MCP on June 23, 2026. It’s specific, it’s dated, and it’s wrong by exactly one year. Agentforce 3 was announced on June 23, 2025, with its native Model Context Protocol (MCP) client entering pilot access the following month. The bigger, more recent Salesforce MCP news isn’t in June at all.
Hosted MCP Servers reached general availability on April 29, 2026, weeks before the Summer ’26 release even began rolling out. That gave customers a Salesforce-managed way to connect Claude, ChatGPT, or Cursor directly to CRM data without building a custom integration. Once that timeline is straight, the more useful question is what actually changes for a team running on Salesforce. Does a vendor’s own hosted MCP server loosen lock-in, or just move it somewhere less visible?
Teams evaluating Salesforce’s AI roadmap ask a version of this question often, and the date confusion tends to stand in for a more useful one. This piece lays out the real timeline, what Hosted MCP Servers change for a Salesforce-only stack versus a multi-vendor one, and where the security tradeoffs sit once the announcement language is set aside.
Salesforce MCP Timeline
Three separate milestones get collapsed into one in a lot of coverage. They are not the same event, and the gap between them shows how enterprise MCP adoption actually unfolds.

June 2025 Pilot
Salesforce announced Agentforce 3, its first release with a native MCP client, which entered pilot access the following month. Agents could connect to any MCP-compliant server without custom code, MuleSoft could convert existing APIs into MCP servers, and Heroku offered a hosting path for custom servers. AgentExchange launched alongside it with more than 30 partner connectors, including AWS, Box, PayPal, and Stripe.
December 2025 AAIF Membership
Salesforce joined the Agentic AI Foundation (AAIF), the Linux Foundation body that now governs MCP, as a Gold member. SAP, Snowflake, and Shopify joined at the same tier. Salesforce held a formal governance stake in MCP’s future four months before shipping a general-availability hosted server.
April 2026 GA Release
Salesforce Hosted MCP Servers reached general availability on April 29, weeks before the Summer ’26 release itself began rolling out. Standard servers for the Salesforce Platform, Data 360, and Tableau shipped generally available, alongside MuleSoft and Slack. A Data 360 MCP Server entered developer preview the following month, and Marketing Cloud Engagement shipped its own hosted MCP server as generally available on June 2, several weeks ahead of the July rollout Salesforce had originally targeted.
That third milestone is the one worth unpacking, because “Hosted MCP Servers” covers two genuinely different things depending on what you’re trying to build.
How Salesforce Hosted MCP Servers Work

The general availability (GA) release splits into two categories, and the difference between them determines how much work lands on your team.
Standard hosted servers are pre-built and maintained by Salesforce, covering SObject CRUD and SOQL queries, Data 360 queries and graph traversal, and Tableau analytics. Point an MCP-compatible client at one, authenticate with OAuth, and the tool surface is already defined.
Custom hosted servers cover everything a standard server doesn’t, built from Apex invocable actions, autolaunched Flows, Apex REST endpoints, @AuraEnabled methods, Named Query API SOQL, or Prompt Builder prompts. Salesforce hosts the server, so there’s no separate infrastructure to run, and every connection still goes through OAuth. Custom servers also inherit your org’s existing sharing and security model, a meaningfully different starting point than a self-hosted server with no permission model at all. Invoking an existing Agentforce agent as a callable tool wasn’t part of the April GA. Salesforce lists it as coming soon, so treat it as a roadmap item, not something you can build on today.
| Parameter | Standard Hosted Servers | Custom Hosted Servers |
|---|---|---|
| Built by | Salesforce | Your team, from Apex, Flows, or Prompt Builder |
| Setup | Enabled in Setup, no code | Requires writing the underlying Apex or Flow |
| Covers | SObject data, Data 360, Tableau | Anything a standard server doesn’t expose |
| Security model | Managed entirely by Salesforce | Inherits org sharing rules, but only as strict as the class it’s built from |
A standard server is the right call for reading and writing CRM data with no code. Triggering business logic still means writing the same Apex you’d write for a traditional API integration, just exposed through MCP instead of a bespoke API.
None of this happened in a vacuum, and that context matters for judging how big a deal it actually is.
Salesforce Joins an MCP Pattern
Coverage that frames this as Salesforce validating MCP alone misses the bigger pattern. Salesforce is joining a group of major enterprise platforms that had already begun shipping native MCP support, not opening the door on its own.
Microsoft introduced a static, 13-tool Dynamics 365 ERP MCP server at Build 2025 in May 2025. That gave way to a dynamic version, exposing hundreds of thousands of ERP functions through data and form tools, reaching public preview in November 2025. A separate Dynamics 365 Sales MCP server ships alongside it.
ServiceNow introduced its own MCP Server Console in December 2025. It lets any MCP-compliant client, including Claude and Copilot, discover and invoke governed ServiceNow tools without a custom connector per vendor. HubSpot moved earlier still, shipping a Deep Research MCP connector for ChatGPT in June 2025.
| Vendor | First Native MCP Support | Hosted / Server-Side MCP |
|---|---|---|
| Microsoft | Static Dynamics 365 ERP MCP server (13 tools), Build May 2025 | Dynamic ERP MCP server, public preview, November 2025 |
| HubSpot | Deep Research MCP connector for ChatGPT, June 2025 | No separate hosted-server milestone reported |
| Salesforce | Native MCP client in Agentforce 3, pilot access, June–July 2025 | Hosted MCP Servers, general availability, April 29, 2026 |
| ServiceNow | MCP client support in AI Agent Studio, 2025 | MCP Server Console, general availability, December 2025 |
Put side by side, Salesforce’s release reads less like a company placing a bet and more like the last major CRM and ERP vendor confirming one the rest of the category had already made, one more data point in why MCP is becoming the default for AI integration. That’s a stronger form of validation than any single vendor moving first, since it shows MCP’s traction inside enterprise software didn’t depend on one company’s roadmap.
Validation from three platforms is one signal. The adoption numbers behind it are another worth checking against a real source rather than the figures currently making the rounds.
What MCP Adoption Data Shows
There’s a genuine growth story here, worth citing precisely rather than gesturing at fast growth.
Download and Server Growth
As of Anthropic’s own December 9, 2025 update, MCP had reached 97 million monthly SDK downloads across Python and TypeScript, with more than 10,000 active public servers. That’s the most recent figure traceable to a primary source, so treat anything newer with caution until it’s confirmed against Anthropic’s own reporting.
The Real Production Number
Adoption inside production is harder to pin down. A widely repeated claim that 78 percent of enterprise AI teams have MCP in production doesn’t trace back to a named, checkable survey. Stacklok’s 2026 State of MCP in Software report puts the real number closer to 41 percent, combining limited and broad production use, meaningfully smaller than the figure still circulating.
What’s Still Unresolved
Big-vendor adoption doesn’t mean the protocol is finished. MCP’s own maintainers published a 2026 roadmap naming enterprise readiness, transport scalability, and governance maturity as unresolved priorities. Salesforce, Microsoft, and ServiceNow building hosted servers is real signal the protocol works for production CRM and ERP data. That’s a narrower claim than saying every open question at enterprise scale has been resolved.
Governance maturity is the unresolved part worth sitting with, since it shows up immediately in how these three vendors deployed their servers.
The Vendor Lock-In Problem

Coverage of this release consistently misses one point. An open, vendor-neutral protocol doesn’t automatically make a deployment vendor-neutral.
Salesforce’s hosted MCP servers run inside Salesforce’s own OAuth flow and governance layer. Microsoft’s Dynamics 365 MCP servers run inside Microsoft’s. ServiceNow’s run inside ServiceNow’s. An agent stack touching Salesforce records, a Dynamics ERP process, and a ServiceNow ticket in the same workflow still has to manage three separate hosted endpoints, OAuth connections, and rate limits. All three speak the same protocol, but that doesn’t collapse them into one connection.
Standardization happened at the wire-protocol level, not at the level of giving a team one place to manage all of an agent’s tool access, since that was never MCP’s job. Salesforce’s own GA announcement points at the fix by name. It describes a new category of “MCP gateways” emerging to manage this at the enterprise level, tools that do for MCP traffic what an API gateway does for REST calls. Standardizing how an agent reaches multiple vendor-hosted MCP servers under one integration, Salesforce included, is exactly that gap. It’s where MCP360 sits.
Trusting a vendor’s governance model for standard servers is one thing. What happens once a team builds its own custom servers on top of that model is a different question, and it deserves a straight answer.
MCP Server Security
A meaningful share of what Salesforce shipped involves custom servers built on Apex, Flows, and API Catalog endpoints, which is why this earns its own section rather than a line in the feature list.
A custom MCP server is only as safe as the Apex action or Flow it wraps. Exposing an invocable method as an MCP tool means any authorized client can call it however an AI agent decides to, beyond the original UI’s call pattern. This is worth reading alongside how MCP replaces unstructured API access with structured, declared tool calls, since that structure is exactly what makes an exposed Apex method auditable in the first place.
Summer ’26 also changed two relevant Apex defaults, for classes saved at API version 67.0 or later.
- Database operations now default to user mode instead of system mode.
- Classes without an explicit sharing declaration now default to with sharing instead of without sharing.
That’s safer than prior releases, though it still depends on the class’s configuration and API version. A custom tool built from a class that explicitly declares without sharing bypasses that protection regardless of the platform default.
OAuth on every connection is the baseline Salesforce provides. Whether it respects an org’s field-level security and sharing rules depends on how the underlying Apex, Flow, or API Catalog entry was built, the same governance discipline any integration requires. A new custom MCP server deserves the same scoping and security review as a new integration user. Define what it can touch before publishing it, not after.
Frequently Asked Questions
What is Salesforce MCP?
Salesforce MCP is Salesforce’s implementation of the Model Context Protocol, the open standard that lets AI tools like Claude, ChatGPT, or Cursor connect to Salesforce data, flows, and Apex actions instead of relying on custom-built API integrations for each client.
What is an MCP gateway?
An MCP gateway sits between AI agents and multiple MCP servers, so tools load through one connection instead of a custom integration per vendor. MCP360 is built specifically for this role, giving teams a single API key and one access point across every MCP server they connect to.
When did Salesforce Hosted MCP Servers become generally available?
Salesforce Hosted MCP Servers reached general availability on April 29, 2026, several weeks before the broader Summer ’26 release rolled out. This is a separate milestone from Agentforce 3’s native MCP client, which was announced back in June 2025.
Is Salesforce the first company to support MCP natively?
No. Microsoft, HubSpot, and ServiceNow shipped native MCP support before Salesforce, between May and December 2025. Salesforce’s Hosted MCP Servers reached general availability in April 2026, the third major platform to ship native, server-side MCP support. Teams running more than one platform use MCP360 to manage them from a single integration.
What’s the difference between standard and custom Salesforce MCP servers?
Standard hosted servers are pre-built by Salesforce and cover common needs like SObject data, Data 360, and Tableau, ready to use with no code. Custom hosted servers are ones you build yourself from Apex actions, Flows, or Prompt Builder templates, giving you control over exactly which tools an AI agent can call.
Is Salesforce MCP secure?
Every Salesforce MCP connection goes through OAuth and inherits your org’s existing security and sharing rules. Protection still depends on how the underlying Apex or Flow is configured, so a poorly scoped custom server can expose more data than intended.
How do I connect Claude to Salesforce?
Point Claude at one of Salesforce’s Hosted MCP Servers and authenticate with OAuth, the same connection method used by any MCP-compatible client. No custom API integration is required, since the tool surface is already defined by the server you connect to.
Does adopting MCP mean avoiding vendor lock-in?
Not automatically. MCP is an open protocol, but each vendor’s hosted MCP server still runs inside that vendor’s own OAuth and governance layer. A team using Salesforce, Microsoft, and ServiceNow still manages three separate connections. MCP360 gives teams one integration point across all of them instead, without adding another governance layer to maintain.
Conclusion
Salesforce’s MCP news reads like a single bold pivot, but a ten-month build-out landing roughly where Microsoft and ServiceNow already stood tells a steadier story. Correcting the timeline reframes the release as routine platform investment, not a headline built to impress.
Treat general availability as a scoping exercise, not a finish line. Point MCP-compatible clients at Salesforce data through the governed hosted servers now available, and audit what any custom server exposes before an agent can call it. Three major platforms shipping native MCP support still haven’t solved cross-vendor access. Teams already managing more than one of these hosted servers can see what a single-integration approach looks like at MCP360.
MCP standardizes how agents talk to tools. It doesn’t standardize how organizations govern them. The vendors worth watching next will be judged less on whether they support MCP, and more on how much of that governance work they still leave enterprises to do alone.
Article by
HarsheenMCP & AI Agents | Content Writer
Harsheen is a content writer covering AI agents, automation, and no-code tools. She writes across topics from chatbots and customer experience to MCP and enterprise workflows, showing how real teams adopt AI in everyday operations.




