Install AI Tools

B2C Commerce tools, documentation, and skills for your assistant.

Claude

Install the plugin Recommended

bash
claude plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
claude plugin install b2c-dx-mcp@b2c-developer-tooling --scope project

Start a new Claude Code session in your project. Use --scope user instead for all projects.

Manual MCP setup

From your project directory:

bash
claude mcp add --transport stdio --scope project b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new session. Use --scope user instead for all projects. See Claude Code MCP setup.

Claude Desktop setup

Codex

Install the plugin Recommended

bash
codex plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
codex plugin add b2c-dx-mcp@b2c-developer-tooling

Start a new Codex session in your project. This setup also works with the Codex IDE extension and the ChatGPT Work desktop app.

Manual MCP setup
bash
codex mcp add b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Or add this to ~/.codex/config.toml (or $CODEX_HOME/config.toml if customized):

toml
[mcp_servers.b2c-dx-mcp]
command = "npx"
args = ["-y", "@salesforce/b2c-dx-mcp@latest"]

Start a new session. See Codex MCP configuration.

ChatGPT online setup

VS Code

Install the plugin Recommended

  1. Open the Command Palette (Cmd/Ctrl+Shift+P) and run Chat: Install Plugin from Source.
  2. Enter SalesforceCommerceCloud/b2c-developer-tooling.
  3. Select b2c-dx-mcp and follow the installation prompts.
  4. Start a new chat in GitHub Copilot.
Manual MCP setup

Add this to .vscode/mcp.json in your workspace:

json
{
  "servers": {
    "b2c-dx-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

See VS Code MCP setup.

Copilot CLI setup

Cursor

Reload the MCP server in Cursor after installation.

Manual MCP setup

Add this to .cursor/mcp.json in your project:

json
{
  "mcpServers": {
    "b2c-dx-mcp": {
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

For all projects, use ~/.cursor/mcp.json instead.

See Cursor's MCP documentation.

OpenCode

Add this to opencode.json in your project:

json
{
  "mcp": {
    "b2c-dx-mcp": {
      "type": "local",
      "command": ["npx", "-y", "@salesforce/b2c-dx-mcp@latest"],
      "enabled": true
    }
  }
}

Restart OpenCode. For all projects, use ~/.config/opencode/opencode.json. See OpenCode MCP setup.

Gemini

From your project directory, run:

bash
gemini mcp add --scope project b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new Gemini CLI session. Use --scope user instead for all projects. See Gemini CLI MCP setup.

No separate skills plugins needed.

Other clients and manual setup →
Skip to content
View as Markdown
View as Markdown

@salesforce/b2c-tooling-sdk / auth / AuthStrategy

Interface: AuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:17

Extended by

Methods

fetch()

fetch(url, init?): Promise<Response>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:22

Performs a fetch request with authentication. Implementations MUST handle header injection and 401 retries (token refresh) internally.

Parameters

url

string

init?

FetchInit

Returns

Promise<Response>


getAccessTokenForCascade()?

optional getAccessTokenForCascade(candidates): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:71

Optional: Resolves a scope cascade by trying each candidate scope set in order and returning the first that AM accepts.

Implementations should:

  1. Return any cached token whose scopes ⊇ a candidate (no AM call).
  2. Otherwise, call AM with each candidate in order until one survives; cache the result keyed by what was requested.
  3. Throw the last invalid_scope error if all candidates fail.

Implementations MUST add any base scopes (e.g. tenant scope baked in via withAdditionalScopes) to each candidate before sending it to AM.

Used by the SCAPI auth middleware to pick the right scope tier (rw vs ro) per operation. Strategies without OAuth-style scope grants (basic, api-key) should leave this unset; the middleware falls through to getAuthorizationHeader in that case.

Parameters

candidates

string[][]

Outer array is cascade order; inner arrays are the scopes for each token request attempt. e.g. [['sfcc.jobs.rw'], ['sfcc.jobs']].

Returns

Promise<string>

The access token (Bearer value, no Bearer prefix).


getAuthorizationHeader()?

optional getAuthorizationHeader(): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:27

Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.

Returns

Promise<string>


invalidateToken()?

optional invalidateToken(): void

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:33

Optional: Invalidates the cached token, forcing re-authentication on next request. Used by middleware to retry requests after receiving a 401 response.

Returns

void


withAdditionalScopes()?

optional withAdditionalScopes(additionalScopes): AuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:45

Optional: Returns a copy of this strategy with the given scopes merged into its requested scope set. SCAPI client factories use this to ensure the tenant scope is present on every token request.

Implemented by OAuthStrategy and JwtOAuthStrategy. Strategies that obtain tokens by other means (basic, api-key, implicit-via-stored-session) may not implement this; callers should treat them as "scopes already established at construction time."

Parameters

additionalScopes

string[]

Returns

AuthStrategy