anthropics / anthropics/claude-ai-mcp
Salesforce Hosted MCP Sandbox connector fails with invalid_client_id — Enhanced Domains org redirected to legacy test.salesforce.com instead of My Domain
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 471
- Fork
- 77
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### What happened?
No ofid_ reference ID exists for this failure — Salesforce rejects the request on its own
OAuth domain (test.salesforce.com) before any response reaches Claude's systems, so nothing
is logged on Claude's side to generate one.
Occurred: 12:14 AM EST
MCP server URL: https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-reads
Connecting via: Custom connector, manually entered
Where it fails: Immediately on the Salesforce OAuth authorize redirect, before any login form renders
Error:
test.salesforce.com/services/oauth2/authorize returns
error=invalid_client_id&error_description=client%20identifier%20invalid
Confirmed NOT a configuration issue — External Client App verified correct in every respect:
- Consumer Key matches exactly what's registered in the Claude connector
- Enable OAuth on; scopes: api, refresh_token/offline_access, mcp_api
- Callback URL: https://claude.ai/api/mcp/auth_callback
- Security: PKCE required, "require secret" unchecked (Web Server + Refresh Token flows),
JWT-based access tokens for named users enabled
- Permitted Users: Admin approved users are pre-authorized, correct Permission Set assigned
- App Status: Enabled
Root cause: this Sandbox has Enhanced Domains enabled
(My Domain: [company]--[sandbox].sandbox.my.salesforce.com). Salesforce's Spring '26 release
permanently ended legacy hostname (test.salesforce.com/login.salesforce.com) support for OAuth
on Enhanced Domains orgs, with no re-enable option. The OAuth redirect needs to resolve to the
org's actual My Domain URL instead — see github.com/n8n-io/n8n/issues/28990 for an unrelated
integration hitting the identical root cause on Salesforce Sandboxes.
This explains why our Production Salesforce connector (same setup pattern) still works: per
the linked n8n report, Salesforce is enforcing this sandbox-first, with production expected to
be affected on the same timeline.
### What did you expect to happen?
Expected the Connector to let me connect to our Sandbox environment.
### Steps to reproduce
1. Add https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-reads as a custom
connector (Organization Settings → Connectors → Add → Custom → Web), using the Client ID
from a correctly configured Salesforce External Client App in a Sandbox org with Enhanced
Domains enabled
2. Click Connect on the connector from Customize → Connectors
3. Browser hands off to test.salesforce.com/services/oauth2/authorize with the correct client_id
4. Salesforce immediately returns error=invalid_client_id, before any login form renders
### Area
MCP Connector (adding/managing servers)
### MCP Server (if applicable)
_No response_
### Error messages or logs
```shell
test.salesforce.com/services/oauth2/authorize?response_type=code&client_id=3MVG98bly0AKZIIWkqBOTEkqut...
error=invalid_client_id&error_description=client%20identifier%20invalid
No ofid_ exists for this failure — occurs on Salesforce's own OAuth domain before any response
reaches Claude's systems. Occurred 12:14 AM EST.
```
### Additional context
Confirmed NOT a configuration issue — External Client App verified correct in every respect:
- Consumer Key matches exactly what's registered in the Claude connector
- Enable OAuth on; scopes: api, refresh_token/offline_access, mcp_api
- Callback URL: https://claude.ai/api/mcp/auth_callback
- Security: PKCE required, "require secret" unchecked (Web Server + Refresh Token flows),
JWT-based access tokens for named users enabled
- Permitted Users: Admin approved users are pre-authorized, correct Permission Set assigned
- App Status: Enabled
Root cause: this Sandbox has Enhanced Domains enabled. Salesforce's Spring '26 release
permanently ended legacy hostname (test.salesforce.com/login.salesforce.com) support for OAuth
on Enhanced Domains orgs, with no re-enable option — see github.com/n8n-io/n8n/issues/28990
for an unrelated integration hitting the identical root cause.
Production connector (same pattern) still works — Salesforce is enforcing this sandbox-first.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Start at the custom connector's OAuth authorization setup for sandbox MCP servers and trace why it emits test.salesforce.com rather than the org's My Domain URL. Reproduce with the supplied sandbox URL and Enhanced Domains configuration; done means the redirect reaches Salesforce on the sandbox My Domain and the connection completes without invalid_client_id.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Ambito
- api, authentication
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Attiva
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 48/100