Agent skill

Experience Portal Create

by forcedotcom in forcedotcom/sf-skills

Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP…

Apache-2.0Auto-check: notesSales & Support

Install Experience Portal Create

skills CLI
$ npx skills add forcedotcom/sf-skills --skill experience-portal-create -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills experience-portal-create --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/experience-portal-create .claude/skills/experience-portal-create && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
experience-portal-create
GitHub stars
1.1k
Token cost
~7.2k tokens
SKILL.md length
3,015 words
Files
5 (incl. references, assets)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP…

  • Works in 4 steps: Determine API Based on Portal Type → Create Portal (By Type) → Make the Site Reachable — Activate, Add… → …
  • A user asks to create/provision/set up a portal
  • SKILL.md covers Scope, Execution model (read first), Clarifying Questions and Required Inputs, plus 8 more sections
  • Calls sf

What it does

Experience Portal Create is an agent skill from forcedotcom/sf-skills. Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP site-creation APIs. Use whenever a user asks to create/provision/set up a portal, site, or community, e.g.: 'create an employee service portal', 'create an IT Support Portal', 'create an Agentforce Employee Center', including wiring MIAW (Messaging for In-App/Web) at create. This is the site-CREATION skill and OWNS…

Its SKILL.md is about 7.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/report-template.md`, `references/mcp-invocation.md` and `references/post-creation-activate-publish.md`).

It sits in Sales & Support, covering Customer support. It works with Model Context Protocol and Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • A user asks to create/provision/set up a portal
  • E.g.: create an employee service portal
  • Create an IT Support Portal
  • Create an Agentforce Employee Center

Example prompts

  • “create an employee service portal”
  • “create an IT Support Portal”
  • “create an Agentforce Employee Center”
  • “/experience-portal-create”

Requirements

  • Pre-approved tools (allowed-tools): Read, AskUserQuestion, Bash, mcp__headless-360__discover, mcp__headless-360__describe, mcp__headless-360__dispatch, mcp__headless-360__dispatch_readonly

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Determine API Based on Portal Type
  2. Create Portal (By Type)
  3. Make the Site Reachable — Activate, Add Members, Publish
  4. Write the Portal Creation Report (always — final step)

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • AskUserQuestion
    • Bash
    • mcp__headless-360__discover
    • mcp__headless-360__describe
    • mcp__headless-360__dispatch
    • mcp__headless-360__dispatch_readonly

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Experience Portal Create loads about 7.2k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 262 tokens; SKILL.md has 3,015 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~262
When it runs · the whole SKILL.md, loaded when a task matches
~7.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, AskUserQuestion, Bash, mcp__headless-360__discover, mcp__headless-360__describe, mcp__headless

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 3,015 words, ~7,203 tokens.

Download SKILL.mdSave it as .claude/skills/experience-portal-create/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
experience-portal-create
description
Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP site-creation APIs. Use whenever a user asks to create/provision/set up a portal, site, or community, e.g.: 'create an employee service portal', 'create an IT Support Portal', 'create an Agentforce Employee Center', including wiring MIAW (Messaging for In-App/Web) at create. This is the site-CREATION skill and OWNS provisioning a new Aura OR LWR Experience Builder site from scratch — trigger it even when the user says 'Experience Builder site' or 'LWR site', as long as a NEW site is wanted. It always writes a portal-creation report as its final step (never ad hoc via CLI) and never makes a legacy Tabs+Visualforce site. DO NOT TRIGGER only for modifying an EXISTING site's pages/routes/theme/branding/guest-access metadata (experience-lwr-site-generate), existing-site customization (experience-ui-bundle), CMS, Commerce.
allowed-tools
Read, AskUserQuestion, Bash, mcp__headless-360__discover, mcp__headless-360__describe, mcp__headless-360__dispatch, mcp__headless-360__dispatch_readonly
metadata.version
1.0
metadata.domains
Experience
metadata.minApiVersion
67.0
metadata.relatedSkills
experience-lwr-site-generate

Create Digital Experience Portal

Create a new Digital Experience (formerly Communities) portal/site in Salesforce. Supports employee service portals, partner portals (PRM), and general customer communities.

Every operation runs through the headless-360 MCP server (mcp__headless-360__discover → mcp__headless-360__describe → mcp__headless-360__dispatch / mcp__headless-360__dispatch_readonly). Do not use the Salesforce CLI (its api request, data query, or org open subcommands), the project-codey MCP server, raw curl, or any other HTTP client — dispatch/dispatch_readonly is the only way this skill talks to the org. See references/mcp-invocation.md for the exact call shapes.

Scope

  • In scope: Creating Digital Experience sites via the headless-360 Connect API dispatcher. Portal type selection. Basic configuration (name, URL, templates). Self-service portals with embedded service configs. Making the site reachable end to end — activating the Network (status: Live), adding member profiles, and publishing the Experience Builder pages (see references/post-creation-activate-publish.md).
  • Out of scope: Deep post-creation customization (page layout/component authoring in Builder). Content authoring. Branding beyond initial setup. Individual per-user record management (membership is added at the profile/permission-set level, not per user).

Execution model (read first)

Every org call is a dispatch: mcp__headless-360__dispatch_readonly(url, method: "GET", queryParams) for reads, mcp__headless-360__dispatch(url, method, body) for writes; read status_code + body from the response. To resolve the endpoint for a portal type, use mcp__headless-360__discover(query=...) and mcp__headless-360__describe(id=...) as needed. Connect API create/list operations for Experience Cloud are not always indexed by discover/describe — when a lookup returns nothing, dispatch the well-known versioned Connect API path directly (see references/mcp-invocation.md) rather than concluding the capability is missing.

Critical: paths must include the full /services/data/vXX.0/... prefix (e.g. "/services/data/v67.0/connect/communities") — unlike some other dispatchers, headless-360 does not resolve or inject the API version for you. A path without the version prefix returns 400 ROUTE_NOT_FOUND. Copy the path verbatim from a discover/describe result when available; otherwise use the version shown in this skill's examples (v67.0 at time of writing) and adjust if the org runs a different version. Full details, response envelope, job-monitoring, and gotchas live in references/mcp-invocation.md.


Clarifying Questions

Before proceeding, determine:

  1. Portal type?

    • Employee Service / ITSM / HR / help desk → prefer the Agentforce Employee Center Aura template via the communities API (richest employee experience; Agentforce-ready). Use the self-service API instead when MIAW must be wired in at creation time and a guest ESD exists.
    • Partner Portal (PRM) → requires PRM feature enabled
    • Customer Community → general community creation (Aura or LWR Experience Builder template)
  2. Basic settings (required for all types):

    • Portal name?
    • URL prefix? (must be alphanumeric only, no hyphens or spaces)
    • Description (optional)
  3. For Employee Service / Self-Service portals:

    • siteType? → default AURA (Aura Experience Builder + Builder). Use LWR only if the user explicitly wants a Lightning Web Runtime site. Never create a Salesforce Tabs + Visualforce ("VF Template") site — those are legacy and have no Builder.
    • MIAW / Embedded Service Deployment ID(s)? These wire Messaging for In-App and Web into the portal at creation time. A guest ESD config is required by the self-service API; an authenticated-user ESD config is optional. If the user hasn't created an Embedded Service Deployment yet, point them to Setup → Embedded Service Deployments first.
  4. For Partner portals only:

    • PRM template name? (check org-specific templates)

Required Inputs

Employee Service / Self-Service Portals (POST /connect/self-service/site):
  • siteName (required) - portal name
  • guestEmbeddedServiceConfigId (required) - Embedded Service Deployment (MIAW) config ID for guest users
  • embeddedServiceConfigId (optional) - Embedded Service Deployment (MIAW) config ID for authenticated users
  • siteType (optional) - AURA (default) or LWR. Produces an Experience Builder site. Do not use Visualforce.
  • enableForGuest (optional) - whether guest (unauthenticated) users can access the site
  • contentDocumentId (optional) - ContentDocument ID of a logo image to wire into the site's branding set
  • brandColors (optional) - array of RGBA colors targeting action, link, border, text, pageBackground

This API sets the URL path prefix automatically from the site name. There is no templateName — the framework is chosen with siteType (Aura/LWR), never Visualforce.

Partner Portals (PRM):
  • siteName (required)
  • siteUrlPrefix (required)
  • prmTemplate (required)
  • siteDesc (optional)
General Communities (POST /connect/communities):
  • name (required)
  • urlPathPrefix (required) - alphanumeric only, no hyphens
  • templateName (required) - an Experience Builder template. Aura: Agentforce Employee Center (preferred for employee service), Employee Portal, Customer Service, Help Center, Customer Account Portal, Partner Central, Build Your Own. LWR: Build Your Own (LWR), Microsite (LWR). Validate the exact string via GET /connect/communities/templates (see below). Do not use Salesforce Tabs + Visualforce ("VF Template") — it is a legacy Visualforce site with no Builder.
  • description (optional)

Workflow

Step 1: Determine API Based on Portal Type
  1. Employee Service / Self-Service → POST /connect/self-service/site

    • Creates an Aura (or LWR) Experience Builder site — never Visualforce
    • Wires MIAW (Embedded Service Deployment) into the site at creation time
    • Prerequisites: CustomizeApplication permission; org has self-service site-creation API access; a guest Embedded Service Deployment exists
  2. Partner (PRM) → POST /connect/prm/setup/sites

    • Prerequisites: CommonPrmEnabled feature
  3. General Community → POST /connect/communities

    • Uses an Experience Builder templateName (Aura or LWR) — never Salesforce Tabs + Visualforce
    • Prerequisites: Manage Communities permission (ManageNetworks)

Step 2: Create Portal (By Type)
Option A: Employee Service / Self-Service Portal

Use the self-service site API. It creates an Aura Experience Builder site (with the Builder option) by deploying CustomSite, Network, and ExperienceBundle metadata, then wires MIAW into the site via the given Embedded Service Deployment (ESD) config IDs. This is the correct path for ITSM / IT help desk / employee self-service portals.

API Call (via mcp__headless-360__dispatch):

text
method: "POST"
url:    "/services/data/v67.0/connect/self-service/site"
body:
{
  "siteName": "<portal-name>",
  "siteType": "AURA",
  "guestEmbeddedServiceConfigId": "<guest-ESD-config-id>",
  "embeddedServiceConfigId": "<auth-ESD-config-id>",
  "enableForGuest": true
}

Poll with GET /services/data/v67.0/connect/self-service/site/status/{jobId} via mcp__headless-360__dispatch_readonly.

  • siteType defaults to AURA (Aura Experience Builder + Builder). Pass LWR only if the user explicitly asks for a Lightning Web Runtime site. Never create a Visualforce site.
  • guestEmbeddedServiceConfigId is required — it is the MIAW Embedded Service Deployment config ID for guest users. embeddedServiceConfigId (authenticated users) is optional. If the user has no Embedded Service Deployment yet, have them create one first (Setup → Embedded Service Deployments), or use the MIAW/embedded-service setup skill.
  • Optional branding: contentDocumentId (logo) and brandColors (array of { "type": "action|link|border|text|pageBackground", "color": { "r": 0-255, "g": 0-255, "b": 0-255, "a": 0-1 } }).

Response:

json
{
  "success": true,
  "siteName": "IT Support Portal",
  "urlPathPrefix": "itsupport",
  "siteUrl": "https://domain.my.site.com/itsupport",
  "jobId": "708...",
  "status": "Queued"
}

On success, report Success: — the portal creation started (Aura + Experience Builder); give the name, framework (Aura), jobId, and status, and note it is provisioning in the background (Network, CustomSite, ExperienceBundle metadata + the Embedded Service/MIAW deployment). Next: monitor the job (see 'Background Job Monitoring'), then complete Step 3 (Activate → Add Members → Publish).

On failure, report Failure: with the {error} — see the "Common Errors" section for the causes (missing/invalid guestEmbeddedServiceConfigId, duplicate name/URL prefix, org lacks self-service site-creation API access, missing CustomizeApplication) and their resolutions.


Option B: Partner Portal (PRM)

API Call (via mcp__headless-360__dispatch):

text
method: "POST"
url:    "/services/data/v67.0/connect/prm/setup/sites"
body:
{
  "siteName": "<name>",
  "siteUrlPrefix": "<url-prefix>",
  "siteDesc": "<description>",
  "prmTemplate": "<template-name>"
}

Synchronous — no job polling.

Response:

json
{
  "networkId": "0DB..."
}

On success, report Success: — the partner portal was created; give the name, networkId, siteUrlPrefix, and prmTemplate. Next: find it at Setup → Digital Experiences → All Sites (by Network ID), then complete Step 3 (Activate → Add Members → Publish).

On failure, report Failure: — see "Common Errors" (org lacks PRM/CommonPrmEnabled, invalid PRM template name, duplicate name/URL prefix). PRM templates: Setup → Digital Experiences → Settings → Partner Templates.


Option C: General Community

First, discover valid templates (required — accepted templateName strings vary by org edition/version), via mcp__headless-360__dispatch_readonly:

text
method: "GET"
url:    "/services/data/v67.0/connect/communities/templates"

Response: { "templates": [ { "publisher": "Salesforce", "templateName": "Employee Portal" }, … ], "total": N }. Use a returned templateName verbatim. Prefer an Experience Builder template (Aura or LWR). Never use Salesforce Tabs + Visualforce.

API Call (via mcp__headless-360__dispatch):

text
method: "POST"
url:    "/services/data/v67.0/connect/communities"
body:
{
  "name": "<name>",
  "urlPathPrefix": "<url-prefix>",
  "description": "<description>",
  "templateName": "Agentforce Employee Center"
}

The body accepts only {name, description, templateName, templateParams, urlPathPrefix} — omit templateParams unless you need template-specific config.

For an employee service / ITSM / HR portal, prefer the Agentforce Employee Center template when the org's live template list includes it — it ships IT/HR ticketing, a self-service catalog, a knowledge base, and an Agentforce-ready experience. Fall back to Employee Portal (then Customer Service) for a plainer, non-Agentforce site. Other options by use case: Help Center (Aura knowledge/deflection), Customer Account Portal (Aura authenticated account self-service), Partner Central (Aura PRM), or Build Your Own (LWR) for a modern blank LWR site.

Agentforce Employee Center is two layers. This POST /connect/communities call provisions the site only. The embedded Agentforce conversational assistant is a separate step — create the internal employee agent from its shipped template (EmployeeCopilot__AgentforceEmployeeAgent) via PATCH /services/data/v67.0/headless/invoke/einstein/genai-agentbuilder/create-copilot-from-template (copilotContext.company is required), then activate it and wire it to the site. This skill provisions the site and points the user to that step; full Agentforce setup is out of scope. See references/templates.md.

Response:

json
{
  "jobId": "08P...",
  "message": "Your site is almost ready. To track the site creation status, query the BackgroundOperation object and enter the jobId as the Id.",
  "name": "Customer Community"
}

On success, report Success: — community creation started; give the name, jobId, and message. Next: monitor the job (see 'Background Job Monitoring'), then complete Step 3 (Activate → Add Members → Publish).

On failure, report Failure: — see "Common Errors" (invalid templateName — run GET /services/data/v67.0/connect/communities/templates and use a returned value verbatim; duplicate name/URL prefix; missing Manage Communities permission).


Step 3: Make the Site Reachable — Activate, Add Members, Publish

Creation only provisions the site — it comes back UnderConstruction, admin-only, with unpublished pages, so its URL is not reachable yet (the #1 "my portal doesn't work" cause). Complete three steps, in order: (1) Activate — deploy the Network metadata with <status>Live</status>; (2) Add members — add the target profile(s) to networkMemberGroups (membership is profile-based, not per user; e.g. Unified Employee — a Profile, not a UserRole) and redeploy (combinable with step 1); (3) Publish — sf community publish --name "<Site Name>", then poll the returned jobId on BackgroundOperation until Complete. Then confirm status: Live and give the user the login URL (.../<prefix>/login), not the bare prefix.

Tooling exception: activate/members use the Metadata API (Network deploy) and publish uses sf community publish — there is no Connect API for these (PATCH /connect/communities returns 405). This is the one place the skill uses tools other than headless-360; Step 3 reads still go through headless-360.

Exact commands, XML, verification queries, and gotchas: references/post-creation-activate-publish.md.


Step 4: Write the Portal Creation Report (always — final step)

Always finish by writing a report.md summarizing what was done — this is the skill's final, non-optional action, whether the create call succeeded, is still provisioning, or failed. Write it to the working/output directory as report.md.

The report must:

  • Start with the heading # Portal Creation Report.
  • State the portal name, the API used (self-service/site, communities, or prm) and why (e.g. "no guest ESD present → communities API"), the framework (Aura / LWR), and the template or siteType chosen.
  • Give the dispatched request (path + key body fields) and the response (jobId / networkId / siteUrl / status, or the error).
  • List the remaining Step 3 work (Activate → Add Members → Publish) and, for employee-service sites, note that the embedded Agentforce agent is a separate follow-up step.
  • End with the sentinel line, exactly: Task completed: portal creation dispatched — see report.md

Copy the template at assets/report-template.md and fill in the portal-specific values.


Template Recommendations

All recommendations produce Experience Builder sites (Aura or LWR). Never recommend Salesforce Tabs + Visualforce ("VF Template") — it is legacy and has no Builder.

Use CaseAPIFrameworkTemplate / siteType
Employee service / ITSM / HR / help desk (richest; Agentforce-ready)communitiesAuraAgentforce Employee Center
Employee service / help desk (MIAW at creation, guest ESD exists)self-service/siteAurasiteType: AURA (+ MIAW ESD config)
Employee service / help desk (plainer, no Agentforce)communitiesAuraEmployee Portal (fallback Customer Service)
Customer support / self-service communitycommunitiesAuraCustomer Service
Knowledge base / case deflectioncommunitiesAuraHelp Center
Authenticated account self-servicecommunitiesAuraCustomer Account Portal
Partner portal (with PRM)prm/setup/sitesAuraOrg-specific PRM template
Partner portal / channel (no PRM)communitiesAuraPartner Central
Modern blank / headless-friendly sitecommunitiesLWRBuild Your Own (LWR)

Modern recommendations:

  • For employee service / ITSM / HR portals, prefer the Agentforce Employee Center Aura template via the communities API — it ships the fullest employee experience (ticketing, catalog, knowledge, Agentforce-ready). The conversational assistant is a separate agent step (EmployeeCopilot__AgentforceEmployeeAgent). Use the self-service site API (siteType: AURA) instead when the portal needs MIAW wired in at creation time and a guest Embedded Service Deployment exists; use Employee Portal for a plainer, non-Agentforce site.
  • For customer communities, use the Customer Service template (Aura, mobile-responsive) via the communities API.

See references/templates.md for complete template documentation.


Show full SKILL.md (1,106 more words)Show less

Background Job Monitoring

Portal creation is asynchronous (except PRM which is synchronous). Poll through mcp__headless-360__dispatch_readonly.

Self-service site path — use the dedicated typed status route (preferred):

text
method: "GET"
url:    "/services/data/v67.0/connect/self-service/site/status/{jobId}"

Returns {success, siteName, urlPathPrefix, siteUrl, error, jobId, status}.

Communities path — query BackgroundOperation via the regular REST query endpoint, not /tooling/query:

text
method:      "GET"
url:         "/services/data/v67.0/query"
queryParams: { "q": "SELECT Id, Status FROM BackgroundOperation WHERE Id = '<jobId>'" }

Tooling vs. regular query (verified gotcha): BackgroundOperation is not a valid Tooling API sObject through this dispatcher — GET /services/data/vXX.0/tooling/query with that SOQL returns 400 INVALID_TYPE "sObject type 'BackgroundOperation' is not supported.". Use the plain /services/data/vXX.0/query endpoint instead; it succeeds with the same SOQL string.

Column discipline: on BackgroundOperation, select only Id and Status. JobType, CompletedDate, and NumErrors are not columns on this object and return INVALID_FIELD. Use the SOQL string above exactly.

Job statuses:

  • Queued / Scheduled — waiting to start
  • InProgress / Running — executing
  • Complete — finished successfully
  • Error — failed (check the error field on the status route)

Verification

After creation completes:

  1. API (primary): mcp__headless-360__dispatch_readonly(url: "/services/data/v67.0/connect/communities", method: "GET") lists all Experience Cloud sites. Find the new one and confirm siteAsContainerEnabled: true (Experience Builder — Aura/LWR) and a non-null builderUrl, and that templateName is not Salesforce Tabs + Visualforce. siteAsContainerEnabled: false means a legacy Visualforce site — the bug this skill exists to avoid.
  2. Setup UI (optional): Setup → Digital Experiences → All Sites. The Framework column should show Aura (or LWR) — not Visualforce — with a Builder workspace link.
  3. Test URL: Use siteUrl from the response (portal will be inactive initially).

Note: Portal must be activated and published before external users can access it.


Rules / Constraints

ConstraintRationale
Portal creation is asynchronousDeploys metadata and provisions resources in background
Site names must be uniqueEach portal needs distinct name within org
URL prefixes must be uniqueURL paths cannot conflict
URL prefixes must be alphanumericNo hyphens, spaces, or special characters allowed
PRM requires PRM featureGated by licensing and org config
Created portals start inactiveMust manually activate/publish after creation
Paths must include the API version prefixdispatch/dispatch_readonly do not inject /services/data/vXX.0 — omitting it returns 400 ROUTE_NOT_FOUND

Prerequisites by Type

Employee Service / Self-Service:
  • CustomizeApplication permission
  • Communities/Digital Experience enabled
  • Org has self-service site-creation API access enabled
  • A guest Embedded Service Deployment (MIAW) config exists (its ID is required); optionally an authenticated-user ESD config
Partner (PRM):
  • Org has CommonPrmEnabled
  • Portal creation permissions
  • Valid PRM template name
General Community:
  • Manage Communities permission (ManageNetworks)
  • Communities/Digital Experience enabled
  • Valid template name

Common Errors

Invalid URL prefix:

"The URL can only contain alphanumeric characters. Remove hyphens, spaces, or special characters (e.g., 'employeeservice' not 'employee-service') and try a different prefix."

Invalid template name (general community path):

"The specified template does not exist.

Resolution:

  • Run GET /services/data/v67.0/connect/communities/templates and use a returned templateName verbatim
  • Prefer an Experience Builder template: Agentforce Employee Center (employee service), Employee Portal, Customer Service, Help Center, Customer Account Portal, Partner Central, Build Your Own, Build Your Own (LWR)
  • Template names are case-sensitive — match exactly
  • Do NOT use Salesforce Tabs + Visualforce ("VF Template") — it is a legacy Visualforce site with no Builder"
Missing guest Embedded Service config (self-service path):

"The self-service site API requires a guest Embedded Service Deployment config ID.

Resolution:

  • Create an Embedded Service Deployment (MIAW) at Setup → Embedded Service Deployments, or use the MIAW/embedded-service setup skill
  • Pass its config ID as guestEmbeddedServiceConfigId (and optionally embeddedServiceConfigId for authenticated users)"
PRM not enabled:

"This org doesn't have Partner Relationship Management (PRM) enabled.

Options:

  1. Contact Salesforce to enable PRM feature
  2. Create a general community with the Partner Central template instead (via Communities API)"
Duplicate name/URL:

"A portal with this name or URL prefix already exists (the communities API returns 400 INVALID_INPUT — Enter a different name. That one already exists.).

Check existing portals: mcp__headless-360__dispatch_readonly(url: "/services/data/v67.0/connect/communities", method: "GET") and scan the name / urlPathPrefix fields.

Choose a different name or URL prefix."

Missing permissions:

"You don't have permission to create portals.

Required permissions:

  • Self-service portals: CustomizeApplication
  • General communities: ManageNetworks (Manage Communities)

Contact your Salesforce admin to request these permissions."

Route not found (missing version prefix):

"400 ROUTE_NOT_FOUND on a path that otherwise matches this skill's documentation. Confirm the url includes the full /services/data/vXX.0/... prefix — dispatch/dispatch_readonly require it verbatim and won't add it for you. If a specific version 404s, try the version shown in a recent discover/describe result for that org."


After creation:

  • Activate portal — Setup → Digital Experiences → All Sites → Activate
  • Configure branding — Customize colors, logo, theme
  • Add pages/components — Use Experience Builder
  • Set up user access — Profiles, permission sets, sharing rules
  • Publish portal — Make accessible to external users

Manage existing:

  • List portals — mcp__headless-360__dispatch_readonly(url: "/services/data/v67.0/connect/communities", method: "GET")
  • Update settings — Network Tooling API or Metadata API
  • Deactivate — Via Setup UI

Important Notes

  1. Creation is asynchronous (except PRM) and only provisions — APIs return a job ID and the portal comes back UnderConstruction, member-less, and unpublished, so its URL is not reachable until you complete Step 3 (Activate → Add Members → Publish; see references/post-creation-activate-publish.md).
  2. URL prefix becomes the site path — https://<domain>.my.site.com/<prefix> (serve/login at .../<prefix>/login, not the bare prefix).
  3. Embedded Service / MIAW configs must pre-exist — This skill does not create Embedded Service Deployments. Create them separately at Setup → Embedded Service Deployments (or via the MIAW/embedded-service setup skill), then pass the config IDs to the self-service site API. For general communities, MIAW is added post-creation via an Embedded Service component in Experience Builder.
  4. Template names are case-sensitive — Verify available templates in your org before attempting creation.
  5. discover/describe may not resolve a specific Connect API operation by id — the headless-360 corpus indexes many operations as multi-step SORs rather than single endpoints, and some standard Connect API writes (e.g. POST /connect/communities) are not individually indexed. Do not conclude the capability is missing; dispatch the well-known, versioned Connect API path directly (documented in this skill).

Reference Documentation

  • references/mcp-invocation.md — Read every session. Exact mcp__headless-360__* call shapes, the version-prefix requirement, response envelope, job monitoring, BackgroundOperation column/endpoint discipline, and gotchas.
  • references/templates.md — Available templates, template parameters, selection guide.
  • references/post-creation-activate-publish.md — Step 3 (activate, add members, publish) to make the site reachable: the Metadata-API + sf community publish paths, the 405-on-PATCH gotcha, NetworkMemberGroup column discipline, and the login-URL note.
  • assets/report-template.md — Step 4 report.md template to copy (heading, required fields, sentinel).

API Type Classification

Site creation is dispatched through mcp__headless-360__dispatch / mcp__headless-360__dispatch_readonly (never project-codey or raw HTTP). All paths include the /services/data/vXX.0 prefix. Post-creation (Step 3) is the one exception: activating the Network and adding members use the Metadata API (sf project deploy start --metadata Network:...), and publishing uses sf community publish — there is no Connect API for these (a PATCH /connect/communities/<id> returns 405). Reads/verification for Step 3 still go through headless-360. Creation paths:

  • Self-service portal: Connect API POST /services/data/vXX.0/connect/self-service/site — asynchronous (poll GET /services/data/vXX.0/connect/self-service/site/status/{jobId})
  • PRM portal: Connect API POST /services/data/vXX.0/connect/prm/setup/sites — synchronous
  • General community: Connect API POST /services/data/vXX.0/connect/communities — asynchronous (poll BackgroundOperation via GET /services/data/vXX.0/query, not /tooling/query)

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references, assets) in skills/experience-portal-create of forcedotcom/sf-skills.

  • SKILL.md
  • assets/report-template.md
  • references/mcp-invocation.md
  • references/post-creation-activate-publish.md
  • references/templates.md

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Experience Portal Create next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Experience Portal Create compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Experience Portal Create this skillforcedotcom/sf-skills1.1k—~7.2kAutomated safety check: NotesApache-2.0
Support Ticket Triagezapier/gtm-cheat-codes342—~670Automated safety check: PassMIT
Churn Riskindranilbanerjee/digital-marketing-pro8551 repos~2.4kAutomated safety check: PassMIT
Lead Importindranilbanerjee/digital-marketing-pro8551 repos~3.3kAutomated safety check: PassMIT
Pipeline Updateindranilbanerjee/digital-marketing-pro8551 repos~3.3kAutomated safety check: PassMIT
Zsxqunnoo/zsxq-skill304—~3.8kAutomated safety check: PassMIT

Similar skills

  • Support Ticket Triage

    zapier/gtm-cheat-codes

    Official

    Triage support tickets by pulling helpdesk context, searching issue trackers and knowledge bases in parallel, classifying the issue, and giving reps a recommended next action.

    342 GitHub stars~670 tokensUpdated 2 mo ago
    Sales & SupportAuto-check passed
  • Churn Risk

    indranilbanerjee/digital-marketing-pro

    Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…

    855 GitHub starsUsed in 1 repo~2.4k tokens
    Sales & SupportAuto-check passed
  • Lead Import

    indranilbanerjee/digital-marketing-pro

    Import leads into Salesforce, HubSpot, Zoho, or Pipedrive with validation, deduplication against existing CRM records, lead scoring, consent and compliance checks, and source attribution — then push…

    855 GitHub starsUsed in 1 repo~3.3k tokens
    Sales & SupportAuto-check passed
  • Pipeline Update

    indranilbanerjee/digital-marketing-pro

    Update CRM deals — move stages, change values and close dates, attach notes and activities, create follow-up tasks — with validation against pipeline rules, a before-and-after comparison, and…

    855 GitHub starsUsed in 1 repo~3.3k tokens
    Sales & SupportAuto-check passed
  • Zsxq

    unnoo/zsxq-skill

    知识星球 CLI(zsxq-cli)与底层接口完整操作指南,涵盖星球和内容管理、Skill Pay 微信支付场景。当用户提到知识星球、zsxq、小密圈、星球、登录/认证、发帖、评论、回答、编辑、删除主题、定时发布/定时任务/定时回答、投票、问答主题、markdown 正文、AI…

    304 GitHub stars~3.8k tokensUpdated 17 days ago
    Sales & SupportAuto-check passed
  • Agentforce Generate

    SalesforceAIResearch/agentforce-adlc

    Build, modify, audit, repair, optimize, debug, and deploy agents with Agentforce Agent Script.

    114 GitHub starsUsed in 1 repo~7.4k tokens
    Agent WorkflowsAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Experience Portal Create

What does Experience Portal Create do?

Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP…. Experience Portal Create is an agent skill from forcedotcom/sf-skills. Create / provision / set up a NEW Digital Experience (Communities) / Experience Cloud site — employee service, IT support, help desk, HR, customer, and partner portals — via the headless-360 MCP site-creation APIs.

When should I use Experience Portal Create?

Experience Portal Create fits situations like: A user asks to create/provision/set up a portal; E.g.: create an employee service portal; create an IT Support Portal; create an Agentforce Employee Center.

How do I install Experience Portal Create in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill experience-portal-create -a claude-code`. Or copy the skill folder (skills/experience-portal-create in forcedotcom/sf-skills) into .claude/skills/experience-portal-create in your project. Claude Code loads it when a task matches its description.

How do I install Experience Portal Create in Codex?

Run `npx skills add forcedotcom/sf-skills --skill experience-portal-create -a codex`. Or copy the skill folder (skills/experience-portal-create in forcedotcom/sf-skills) into .agents/skills/experience-portal-create in your project. Codex loads it when a task matches its description.

Can I use Experience Portal Create in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill experience-portal-create -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/experience-portal-create, .gemini/skills/experience-portal-create, .github/skills/experience-portal-create and .opencode/skills/experience-portal-create in your project.

What does Experience Portal Create need to run?

Going by SKILL.md and its folder, Experience Portal Create needs the command-line tools its instructions call (sf). Its frontmatter pre-approves these tools: Read, AskUserQuestion, Bash, mcp__headless-360__discover, mcp__headless-360__describe, mcp__headless-360__dispatch, mcp__headless-360__dispatch_readonly.

Does Experience Portal Create access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Experience Portal Create safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Experience Portal Create use?

Experience Portal Create is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Experience Portal Create use?

About 7.2k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.6k tokens, read only when the agent opens those files.

What are the alternatives to Experience Portal Create?

Skills that share tags, products or a category with Experience Portal Create: Support Ticket Triage (zapier/gtm-cheat-codes, 342 stars), Churn Risk (indranilbanerjee/digital-marketing-pro, 855 stars), Lead Import (indranilbanerjee/digital-marketing-pro, 855 stars) and Pipeline Update (indranilbanerjee/digital-marketing-pro, 855 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Experience Portal Create?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.