Install AI Tools

B2C Commerce tools, documentation, and skills for your assistant.

Claude

Install the plugin Recommended

bash
claude plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
claude plugin install b2c-dx-mcp@b2c-developer-tooling

Start a new Claude Code session. To install for the current project only, run it from your project directory with --scope project.

Manual MCP setup
bash
claude mcp add --transport stdio --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new session. To configure the current project only, run it from your project directory with --scope project. See Claude Code MCP setup.

Claude Desktop setup

Codex

Install the plugin Recommended

bash
codex plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
codex plugin add b2c-dx-mcp@b2c-developer-tooling

Start a new Codex session in your project. This setup also works with the Codex IDE extension and the ChatGPT Work desktop app.

Manual MCP setup
bash
codex mcp add b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Or add this to ~/.codex/config.toml (or $CODEX_HOME/config.toml if customized):

toml
[mcp_servers.b2c-dx-mcp]
command = "npx"
args = ["-y", "@salesforce/b2c-dx-mcp@latest"]

Start a new session. See Codex MCP configuration.

ChatGPT online setup

VS Code

Install the plugin Recommended

  1. Open the Command Palette (Cmd/Ctrl+Shift+P) and run Chat: Install Plugin from Source.
  2. Enter SalesforceCommerceCloud/b2c-developer-tooling.
  3. Select b2c-dx-mcp and follow the installation prompts.
  4. Start a new chat in GitHub Copilot.
Manual MCP setup

Add this to .vscode/mcp.json in your workspace:

json
{
  "servers": {
    "b2c-dx-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

See VS Code MCP setup.

Copilot CLI setup

Cursor

Reload the MCP server in Cursor after installation.

Manual MCP setup

Add this to .cursor/mcp.json in your project:

json
{
  "mcpServers": {
    "b2c-dx-mcp": {
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

For all projects, use ~/.cursor/mcp.json instead.

See Cursor's MCP documentation.

OpenCode

Add this to opencode.json in your project:

json
{
  "mcp": {
    "b2c-dx-mcp": {
      "type": "local",
      "command": ["npx", "-y", "@salesforce/b2c-dx-mcp@latest"],
      "enabled": true
    }
  }
}

Restart OpenCode. For all projects, use ~/.config/opencode/opencode.json. See OpenCode MCP setup.

Gemini

Run:

bash
gemini mcp add --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new Gemini CLI session. To configure the current project only, run it from your project directory with --scope project. See Gemini CLI MCP setup.

No separate skills plugins needed.

Other clients and manual setup →
Skip to content
View as Markdown
View as Markdown

b2c_tooling_sdk.slas ​

SLAS Shopper Login token retrieval.

Mirrors the TypeScript @salesforce/b2c-tooling-sdk/slas subpath export. Provides functions to obtain shopper access tokens from the SLAS Shopper Login service, supporting public (PKCE) and private (client_credentials / HTTP Basic) client flows for both guest and registered customers.

This subpackage is intentionally NOT re-exported from the top-level b2c_tooling_sdk package; import it directly:

python
from b2c_tooling_sdk.slas import get_guest_token

Classes ​

SlasTokenConfig ​

python
class SlasTokenConfig

Configuration for SLAS shopper token retrieval.

Attributes

NameTypeDescription
short_codestrSCAPI short code.
organization_idstrOrganization ID in f_ecom_xxxx_yyy format.
slas_client_idstrSLAS client ID.
site_idstrB2C Commerce site/channel ID.
redirect_uristrOAuth redirect URI.
slas_client_secretstr | NoneSLAS client secret (None = public client).

SlasTokenResponse ​

python
class SlasTokenResponse

Response from SLAS token endpoints.

Attributes

NameTypeDescription
access_tokenstrThe shopper access token (JWT).
refresh_tokenstrThe refresh token for silent renewal.
expires_inintAccess-token lifetime in seconds.
token_typestrThe token type (typically Bearer).
usidstrThe unique shopper identifier.
customer_idstrThe customer identifier.
id_tokenstr | NoneOptional OpenID Connect ID token.

from_dict method ​

python
def from_dict(data: dict[str, Any]) -> SlasTokenResponse

Build a SlasTokenResponse from a raw SLAS JSON body.

SlasRegisteredLoginConfig ​

python
class SlasRegisteredLoginConfig(SlasTokenConfig)

Configuration for registered customer login.

Attributes

NameTypeDescription
shopper_loginstrShopper login/username.
shopper_passwordstrShopper password.

Functions ​

generate_code_challenge ​

python
def generate_code_challenge(verifier: str) -> str

Generate a PKCE code challenge from a code verifier using S256.

Parameters

NameTypeDescription
verifierstrThe code verifier to hash.

Returns: The base64url-encoded (unpadded) SHA-256 hash of the verifier.

generate_code_verifier ​

python
def generate_code_verifier(random_bytes: bytes | None = None) -> str

Generate a cryptographically random PKCE code verifier.

Parameters

NameTypeDescription
random_bytesbytes | NoneOptional raw random bytes to encode (for deterministic tests). When omitted, secrets.token_bytes supplies CODE_VERIFIER_BYTES bytes.

Returns: A 128-character base64url-encoded random string.

get_guest_token ​

python
async def get_guest_token(config: SlasTokenConfig) -> SlasTokenResponse

Retrieve a guest shopper access token from SLAS.

  • Private client (slas_client_secret set): uses the client_credentials grant.
  • Public client (no secret): uses the PKCE authorization-code flow with hint=guest.

Parameters

NameTypeDescription
configSlasTokenConfigSLAS token configuration.

Returns: The token response including access_token and refresh_token.

get_registered_token ​

python
async def get_registered_token(config: SlasRegisteredLoginConfig) -> SlasTokenResponse

Retrieve a registered-customer access token from SLAS.

Uses the /oauth2/login endpoint with shopper credentials, then exchanges the returned authorization code for an access token.

The registered-customer flow is PKCE-protected for both public and private clients: a code_challenge is always presented at the /oauth2/login step, so the matching code_verifier must always be sent at the token exchange with the authorization_code_pkce grant.

  • Public client: PKCE token exchange (no client secret).
  • Private client: PKCE token exchange, plus HTTP Basic authentication using the client secret. The client must NOT drop PKCE, or SLAS rejects the exchange with 400 code_verifier is required.

Parameters

NameTypeDescription
configSlasRegisteredLoginConfigSLAS token configuration including shopper credentials.

Returns: The token response including access_token and refresh_token.