Install AI Tools

B2C Commerce tools, documentation, and skills for your assistant.

Claude

Install the plugin Recommended

bash
claude plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
claude plugin install b2c-dx-mcp@b2c-developer-tooling

Start a new Claude Code session. To install for the current project only, run it from your project directory with --scope project.

Manual MCP setup
bash
claude mcp add --transport stdio --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new session. To configure the current project only, run it from your project directory with --scope project. See Claude Code MCP setup.

Claude Desktop setup

Codex

Install the plugin Recommended

bash
codex plugin marketplace add SalesforceCommerceCloud/b2c-developer-tooling
codex plugin add b2c-dx-mcp@b2c-developer-tooling

Start a new Codex session in your project. This setup also works with the Codex IDE extension and the ChatGPT Work desktop app.

Manual MCP setup
bash
codex mcp add b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Or add this to ~/.codex/config.toml (or $CODEX_HOME/config.toml if customized):

toml
[mcp_servers.b2c-dx-mcp]
command = "npx"
args = ["-y", "@salesforce/b2c-dx-mcp@latest"]

Start a new session. See Codex MCP configuration.

ChatGPT online setup

VS Code

Install the plugin Recommended

  1. Open the Command Palette (Cmd/Ctrl+Shift+P) and run Chat: Install Plugin from Source.
  2. Enter SalesforceCommerceCloud/b2c-developer-tooling.
  3. Select b2c-dx-mcp and follow the installation prompts.
  4. Start a new chat in GitHub Copilot.
Manual MCP setup

Add this to .vscode/mcp.json in your workspace:

json
{
  "servers": {
    "b2c-dx-mcp": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

See VS Code MCP setup.

Copilot CLI setup

Cursor

Reload the MCP server in Cursor after installation.

Manual MCP setup

Add this to .cursor/mcp.json in your project:

json
{
  "mcpServers": {
    "b2c-dx-mcp": {
      "command": "npx",
      "args": ["-y", "@salesforce/b2c-dx-mcp@latest"]
    }
  }
}

For all projects, use ~/.cursor/mcp.json instead.

See Cursor's MCP documentation.

OpenCode

Add this to opencode.json in your project:

json
{
  "mcp": {
    "b2c-dx-mcp": {
      "type": "local",
      "command": ["npx", "-y", "@salesforce/b2c-dx-mcp@latest"],
      "enabled": true
    }
  }
}

Restart OpenCode. For all projects, use ~/.config/opencode/opencode.json. See OpenCode MCP setup.

Gemini

Run:

bash
gemini mcp add --scope user b2c-dx-mcp -- npx -y @salesforce/b2c-dx-mcp@latest

Start a new Gemini CLI session. To configure the current project only, run it from your project directory with --scope project. See Gemini CLI MCP setup.

No separate skills plugins needed.

Other clients and manual setup →
Skip to content
View as Markdown
View as Markdown

Authentication ​

The SDK ships several authentication strategies, each implementing the AuthStrategy protocol — an async fetch(url, ...) that injects credentials and handles token retrieval, caching, retry, and refresh. Everything lives under b2c_tooling_sdk.auth (and the common symbols are re-exported at the top level).

Strategies at a glance ​

StrategyClassUse it for
OAuth client-credentialsOAuthStrategySystem (server-to-server) API access with a client ID + secret
JWT BearerJwtOAuthStrategySystem access using a signed JWT (certificate + key) instead of a secret
PKCE (interactive)PkceOAuthStrategyUser/browser login with Authorization Code + PKCE
ImplicitImplicitOAuthStrategyLegacy interactive browser login
BasicBasicAuthStrategyWebDAV / OCAPI Basic auth with username + password
API keyApiKeyStrategySending a static API key header

OAuthMethod values are "client-credentials", "jwt", "user" (PKCE with implicit fallback), "implicit", "basic", and "api-key"; the full set is available as ALL_AUTH_METHODS.

OAuth client-credentials ​

The most common non-interactive strategy. Tokens are minted from Account Manager and cached in-process (single-flight per identity + scope set):

python
import asyncio

from b2c_tooling_sdk.auth import OAuthStrategy, OAuthConfig


async def main() -> None:
    auth = OAuthStrategy(
        OAuthConfig(
            client_id="your-client-id",
            client_secret="your-client-secret",
            scopes=["sfcc.products"],
        )
    )
    response = await auth.fetch("https://your-instance.demandware.net/s/-/dw/data/v23_2/sites")
    print(response.status_code)


asyncio.run(main())

JWT Bearer ​

Uses a signed JWT (client certificate + private key) instead of a client secret:

python
from b2c_tooling_sdk.auth import JwtOAuthStrategy, JwtOAuthConfig

auth = JwtOAuthStrategy(
    JwtOAuthConfig(
        client_id="your-client-id",
        cert_path="/path/to/cert.pem",
        key_path="/path/to/key.pem",
        passphrase=None,
        scopes=["sfcc.products"],
    )
)

PKCE interactive login ​

PkceOAuthStrategy performs the Authorization Code + PKCE browser flow. In practice you rarely instantiate it directly — use create_user_auth_strategy, which returns a PkceWithImplicitFallbackStrategy that transparently falls back to the implicit flow when the PKCE grant is unavailable, and persists the resulting session to the shared session store (so a subsequent CLI or Python run reuses it).

python
from b2c_tooling_sdk.auth import AuthCredentials, create_user_auth_strategy

auth = create_user_auth_strategy(
    AuthCredentials(
        client_id="your-public-client-id",
        redirect_uri="http://localhost:8080/callback",
    )
)

Implicit, Basic, and API-key ​

python
from b2c_tooling_sdk.auth import (
    BasicAuthStrategy,
    ApiKeyStrategy,
    ImplicitOAuthStrategy,
    ImplicitOAuthConfig,
)

basic = BasicAuthStrategy("username", "password")
api_key = ApiKeyStrategy("my-api-key")
implicit = ImplicitOAuthStrategy(ImplicitOAuthConfig(client_id="your-client-id"))

Resolving a strategy from credentials ​

Rather than picking a class by hand, hand a flat AuthCredentials bundle to resolve_auth_strategy. It selects the best available method from the allowed_methods you permit (defaulting to the full precedence order):

python
from b2c_tooling_sdk.auth import AuthCredentials, resolve_auth_strategy

auth = resolve_auth_strategy(
    AuthCredentials(
        client_id="your-client-id",
        client_secret="your-client-secret",
        scopes=["sfcc.products"],
    ),
    allowed_methods=["client-credentials", "jwt"],
)

To discover, without side effects, which methods a given credential bundle could satisfy, use check_available_auth_methods.

Sharing sessions with the CLI ​

The auth-session store lives in the same auth-sessions.json file used by the @salesforce/b2c-cli application. Interactive strategies write their tokens there; you can also inspect it directly:

python
from b2c_tooling_sdk.auth import (
    find_auth_session,
    is_auth_session_token_valid,
    list_auth_sessions,
)

session = find_auth_session("your-client-id")
if session and is_auth_session_token_valid(session):
    print("Reusing the token created by `b2c auth login`")

for s in list_auth_sessions():
    print(s.client_id, s.flow, "expires", s.expires_at)

Because the store is shared, the recommended workflow is: log in once interactively with the CLI (b2c auth login), then run Python automation that picks up the same session with no browser prompt. See CLI Interoperability for file locations and the on-disk format.

API reference ​

See the auth section of the API reference for every class and helper.