The metadata-aware Headless 360 MCP Server is designed as a single MCP connection to the breadth of the Salesforce platform. Rather than presenting thousands of unrelated functions as individual tools, the beta server provides four tools backed by a growing library of Salesforce operations.
Its discovery model is intended to help an agent identify the right Salesforce capability at runtime. Salesforce describes a process in which an agent’s request is interpreted and matched against a semantic index of APIs and Skills, returning ranked candidates before the agent invokes an operation.
That makes the server different from a simple collection of raw endpoints. The goal is for an agent to understand what a capability does and how it relates to the organization’s configuration, permissions, workflows, validation, and governance. Salesforce Hosted MCPs provide managed entry points for MCP-aware AI clients, agents, and developer tools, using the Salesforce organization’s existing trust and permissions model.
Developers can connect Salesforce capabilities to tools such as Cursor and Claude Code, while Salesforce positions the broader platform for use by compatible agents and applications. The practical implication is that an external development environment or agent can work with Salesforce metadata and business capabilities without requiring a separate custom integration for every tool.
The broad Headless 360 MCP Server should not be confused with Salesforce’s generally available hosted MCP capabilities. Salesforce’s developer documentation labels the Headless 360 MCP Server a beta service available starting in July 2026. Teams evaluating it should therefore treat its behavior, coverage, and terms as subject to change.
The Data 360 MCP expansion focuses on giving agents governed customer context outside the Salesforce user interface. Salesforce says Data 360 exposes more than 200 APIs as programmable endpoints for AI agents.
The documented use cases include building, transforming, and mapping data, as well as segmenting and activating fields. These operations allow an agent to work with customer data processes from an existing AI or developer environment instead of requiring users to move manually between interfaces.
The distinction between the two MCP surfaces is important:
Together, they point toward a model in which agents can reason over relevant enterprise context and take actions through Salesforce controls, rather than merely retrieve isolated records.
Salesforce’s announcement extends the approach across major parts of its ecosystem, including Marketing, Sales, Service, Commerce, MuleSoft, Informatica, Tableau, and the broader Salesforce platform.
The expansion includes:
The result is broader than an AI connector. Salesforce is attempting to decouple its platform’s underlying capabilities from the browser-based applications through which people have traditionally consumed them.
Salesforce’s own customer examples illustrate the intended payoff. It says Engine launched its EVA AI support agent in 12 days and that the agent now resolves about half of customer-chat interactions without a human agent.
Those figures are useful as an indication of the deployment speed and automation level Salesforce wants Headless 360 to enable. They should not be treated as a general industry benchmark: the figures are vendor-reported results from an individual customer example, and the available material does not establish whether the same outcomes would apply across other organizations.
Headless 360 changes the integration question from “How do we connect this AI tool to Salesforce?” to “Which Salesforce capabilities should be safely consumable by agents, and where should their rules be enforced?” Salesforce’s own developer guidance highlights business-logic enforcement, integration mapping, metadata communication, and validation as key considerations when agents become a new type of platform consumer.
That creates both an opportunity and a responsibility. Reusing native permissions and governance can reduce duplicated logic, but exposing more capabilities to agents also makes metadata quality, authorization, validation, and operational testing more important. An agent-friendly platform still needs clear boundaries around what an agent may discover, invoke, and change.
Salesforce’s expansion therefore signals a shift from selling applications primarily as destinations for human users toward exposing the platform as composable enterprise infrastructure. MCP is the access standard; Headless 360 is the broader architecture; Data 360 supplies governed customer context; and the experience layer provides ways to deliver the resulting actions across more channels. The promise is less custom integration and more reusable, governed capability—but the broadest MCP surface remains a beta and should be evaluated accordingly.