Install AI Tools

B2C Commerce tools, documentation, and skills for your assistant.

Claude

Install the plugin Recommended

bash
claude plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
claude plugin install b2c-dx-mcp@b2c-developer-tooling --scope project

Start a new Claude Code session in your project. Use --scope user instead for all projects.

Manual MCP setup

From your project directory:

bash
claude mcp add --transport stdio --scope project b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new session. Use --scope user instead for all projects. See Claude Code MCP setup.

Claude Desktop setup

Codex

Install the plugin Recommended

bash
codex plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
codex plugin add b2c-dx-mcp@b2c-developer-tooling

Start a new Codex session in your project. This setup also works with the Codex IDE extension and the ChatGPT Work desktop app.

Manual MCP setup
bash
codex mcp add b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Or add this to ~/.codex/config.toml (or $CODEX_HOME/config.toml if customized):

toml
[mcp_servers.b2c-dx-mcp]
command = "npx"
args = ["-y", "@salesforce/b2c-dx-mcp@latest"]

Start a new session. See Codex MCP configuration.

ChatGPT online setup

VS Code

Install the plugin Recommended

  1. Open the Command Palette (Cmd/Ctrl+Shift+P) and run Chat: Install Plugin from Source.
  2. Enter SalesforceCommerceCloud/b2c-developer-tooling.
  3. Select b2c-dx-mcp and follow the installation prompts.
  4. Start a new chat in GitHub Copilot.
Manual MCP setup

Add this to .vscode/mcp.json in your workspace:

json
{
  "servers": {
    "b2c-dx-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

See VS Code MCP setup.

Copilot CLI setup

Cursor

Reload the MCP server in Cursor after installation.

Manual MCP setup

Add this to .cursor/mcp.json in your project:

json
{
  "mcpServers": {
    "b2c-dx-mcp": {
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

For all projects, use ~/.cursor/mcp.json instead.

See Cursor's MCP documentation.

OpenCode

Add this to opencode.json in your project:

json
{
  "mcp": {
    "b2c-dx-mcp": {
      "type": "local",
      "command": ["npx", "-y", "@salesforce/b2c-dx-mcp@latest"],
      "enabled": true
    }
  }
}

Restart OpenCode. For all projects, use ~/.config/opencode/opencode.json. See OpenCode MCP setup.

Gemini

From your project directory, run:

bash
gemini mcp add --scope project b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new Gemini CLI session. Use --scope user instead for all projects. See Gemini CLI MCP setup.

No separate skills plugins needed.

Other clients and manual setup →
Skip to content
View as Markdown
View as Markdown

@salesforce/b2c-tooling-sdk / auth / OAuthStrategy

Class: OAuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:169

OAuth 2.0 Client Credentials authentication strategy.

Implements the client credentials flow for automated/server-side authentication with no user interaction required. Automatically manages token caching, expiration, and 401 retry logic with single-flight token requests to prevent thundering herd on the token endpoint.

Example

typescript
import { OAuthStrategy } from '@salesforce/b2c-tooling-sdk';

const auth = new OAuthStrategy({
  clientId: 'your-client-id',
  clientSecret: 'your-client-secret',
  scopes: ['sfcc.products'],
});

const response = await auth.fetch('https://api.example.com/products');

Implements

Constructors

Constructor

new OAuthStrategy(config): OAuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:180

Creates a new OAuthStrategy instance with the provided OAuth configuration.

Parameters

config

OAuthConfig

OAuth client credentials and optional configuration

Returns

OAuthStrategy

Methods

fetch()

fetch(url, init): Promise<Response>

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:203

Performs a fetch request with OAuth bearer token authentication.

Automatically injects the Authorization header and client ID header with a valid access token. Implements 401 retry logic: if a previously-successful request returns 401, invalidates the cached token and retries once with a fresh token. Does not retry on initial 401 to avoid retrying with bad credentials.

Parameters

url

string

The URL to fetch

init

FetchInit = {}

Optional fetch init options (headers, body, method, etc.)

Returns

Promise<Response>

The fetch response

Implementation of

AuthStrategy.fetch


getAccessTokenForCascade()

getAccessTokenForCascade(candidates): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:307

Resolves a scope cascade. See AuthStrategy.getAccessTokenForCascade.

Each candidate is merged with this strategy's base scopes (e.g. tenant scope baked in via withAdditionalScopes) before being sent to AM.

Cache strategy:

  1. For each candidate, scan the cache for any non-expired token whose scopes ⊇ (base ∪ candidate). First hit wins, no AM call.
  2. On miss, request each candidate from AM in order. Cache successes.
  3. On invalid_scope for a candidate, continue to the next candidate. On any other error, rethrow.

Parameters

candidates

string[][]

Returns

Promise<string>

Implementation of

AuthStrategy.getAccessTokenForCascade


getAuthorizationHeader()

getAuthorizationHeader(): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:232

Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.

Returns

Promise<string>

Implementation of

AuthStrategy.getAuthorizationHeader


getJWT()

getJWT(): Promise<DecodedJWT>

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:240

Gets the decoded JWT payload

Returns

Promise<DecodedJWT>


getTokenResponse()

getTokenResponse(signal?): Promise<AccessTokenResponse>

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:249

Gets the full token response including expiration and scopes. Useful for commands that need to display or return token metadata.

Parameters

signal?

AbortSignal

Returns

Promise<AccessTokenResponse>


invalidateToken()

invalidateToken(): void

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:275

Invalidates cached tokens, forcing re-authentication on next request.

Clears every token for this client/method/AM-host identity — not just the base-scope key — so a 401 retry can't re-use a rejected token that was cached under a merged cascade-scope key.

Returns

void

Implementation of

AuthStrategy.invalidateToken


withAdditionalScopes()

withAdditionalScopes(additionalScopes): OAuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/oauth.ts:286

Creates a new OAuthStrategy with additional scopes merged in. Used by clients that have specific scope requirements.

Parameters

additionalScopes

string[]

Scopes to add to this strategy's existing scopes

Returns

OAuthStrategy

A new OAuthStrategy instance with merged scopes

Implementation of

AuthStrategy.withAdditionalScopes