Agent skill

Experience UI Bundle Mfa Configure

by forcedotcom in forcedotcom/sf-skills

Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.

Apache-2.0Auto-check passedSales & Support

Install Experience UI Bundle Mfa Configure

skills CLI
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .claude/skills/experience-ui-bundle-mfa-configure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
experience-ui-bundle-mfa-configure
GitHub stars
1.1k
Token cost
~4.8k tokens
SKILL.md length
1,808 words
Files
6 (incl. references, assets)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.

  • Works in 6 steps: Resolve the target site (Network) → Generate permission set files → Deploy to org → …
  • : user wants to enable MFA on a community
  • SKILL.md covers Scope, Prerequisites, Required Inputs and Critical Domain Knowledge, plus 6 more sections
  • Calls sf and jq

What it does

Experience UI Bundle Mfa Configure is an agent skill from forcedotcom/sf-skills. Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users. TRIGGER when: user wants to enable MFA on a community, enforce two-factor authentication for portal users, add MFA to a React Experience Site / Web App, configure ForceTwoFactor permission, create MFA permission sets for external users, or troubleshoot MFA not appearing on login. Also triggers on: MFA community, two-factor portal, ForceTwoFactor permission set, MFA Experience Cloud, MFA React site, identity verification community…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files and assets (for example `references/branding.md`, `references/setup.md` and `references/social-login.md`).

It sits in Sales & Support, covering CRM management and Authentication. It works with Salesforce and React. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • : user wants to enable MFA on a community
  • Enforce two-factor authentication for portal users
  • Add MFA to a React Experience Site / Web App
  • Configure ForceTwoFactor permission

Example prompts

  • “/experience-ui-bundle-mfa-configure”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Resolve the target site (Network)
  2. Generate permission set files
  3. Deploy to org
  4. Assign permission sets
  5. Register the permission sets as site members (networkMemberGroups)
  6. Publish and verify

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sf
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Experience UI Bundle Mfa Configure loads about 4.8k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 231 tokens; SKILL.md has 1,808 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~231
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,808 words, ~4,848 tokens.

Download SKILL.mdSave it as .claude/skills/experience-ui-bundle-mfa-configure/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
experience-ui-bundle-mfa-configure
description
Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users. TRIGGER when: user wants to enable MFA on a community, enforce two-factor authentication for portal users, add MFA to a React Experience Site / Web App, configure ForceTwoFactor permission, create MFA permission sets for external users, or troubleshoot MFA not appearing on login. Also triggers on: MFA community, two-factor portal, ForceTwoFactor permission set, MFA Experience Cloud, MFA React site, identity verification community, MFA experience site, ForceTwoFactor permissionset-meta.xml, MFA permissionset-meta.xml. DO NOT TRIGGER when: configuring org-wide MFA for internal users (that's Setup > Identity Verification), building custom login UI components (use experience-ui-bundle-frontend-generate), or generating generic permission sets without MFA context (use platform-permission-set-generate).
metadata.version
1.1
metadata.domains
Experience
metadata.minApiVersion
47.0
metadata.relatedSkills
dx-org-permission-set-assign, experience-ui-bundle-deploy, experience-ui-bundle-frontend-generate, platform-metadata-deploy, platform-permission-set-generate

Enabling MFA on Experience Sites

Enable Multi-Factor Authentication for Experience Site (Community) users by deploying the correct permission sets and verifying the platform-handled MFA challenge flow.

Scope

In scope:

  • Deploying ForceTwoFactor permission set for community users
  • Deploying ApiEnabled permission set (required for post-login API calls)
  • Assigning permission sets to community users
  • Troubleshooting MFA not appearing on login
  • Customizing MFA/login page branding via NetworkBranding metadata

Out of scope — delegate elsewhere:

  • Building custom login UI → experience-ui-bundle-frontend-generate
  • Creating generic permission sets → platform-permission-set-generate
  • Assigning permission sets (if already deployed) → dx-org-permission-set-assign
  • Deploying metadata to org → platform-metadata-deploy
  • Org-wide MFA for internal Salesforce users → Setup > Identity Verification (not a skill)

Prerequisites

Before using this skill, ensure the following are already in place:

PrerequisiteWhy
Experience Cloud site deployed and activeMFA applies to community login — no site means no login flow to protect
Community users exist (or will self-register)Permission sets are assigned to community users; the site must have a community-enabled profile
Customer Community or Customer Community Login license enabledRequired for community user profiles — without it, user creation and profile deployment will fail
Network/Site published at least onceThe site must be reachable at its URL for login + MFA challenge to appear

Note: This skill does NOT handle org setup, license provisioning, or Experience Cloud site creation. If these prerequisites are missing, set them up first via Setup > Digital Experiences > All Sites > New, or deploy your site's base app bundle.


Required Inputs

Gather before acting:

InputHow to determine
Target orgOrg alias for sf CLI commands
Site nameExperience Site (Network) name — resolve via SELECT Id, Name FROM Network (see Step 1); this is the site/Network name, NOT the uiBundles/ app name
Community usersWhich users or profiles to assign MFA to

Critical Domain Knowledge

These facts are non-obvious and frequently cause confusion:

FactDetail
No custom UI neededPlatform renders the MFA challenge page — no React/LWC component required
ForceTwoFactor permissionThe ONLY way to enforce MFA for community users at login
Org Identity Verification checkboxDoes NOT enforce MFA for community/portal users — only for internal users
vforcesite domainMFA challenge page is always served from the underlying Force.com Site domain — this is expected
Always deploy ApiEnabledReact Experience Sites make post-login REST/Connect API calls (sdk.graphql, sdk.fetch); without ApiEnabled they fail with API_DISABLED_FOR_ORG
Social Login / SSO is separate from MFAReact sites render configured Auth Providers via the built-in Social Login component (shipped in 264) — driven by Auth Provider setup, not by the MFA permission sets. See references/social-login.md.
Login-page branding works for React sitesSince 264, the NetworkBranding "Login & Registration" section is shown in Setup for Site Containers, so logo/color/footer can be customized in the UI — Metadata API still works too.

Workflow

Step 1: Resolve the target site (Network)

These are React Experience Sites, so both permission sets are always deployed — ForceTwoFactor (enforces MFA) and ApiEnabled (React sites make post-login API calls).

Resolve the Experience Site's real name and Id from the org — do not assume the uiBundles/ app folder name is the site name. They are frequently different, and the site name must come from the org (the deploy target), not the local project. <site-name> and <NETWORK_ID> below come from here:

bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Name FROM Network" --json
  • One site → use its Name as <site-name> and Id as <NETWORK_ID>.
  • Multiple sites → ask the user which one (show the names).
  • Zero sites → the site isn't deployed yet; stop and tell the user (see Prerequisites).
Step 2: Generate permission set files

First, detect the project's source directory:

bash
jq -r '.packageDirectories[0].path + "/main/default"' sfdx-project.json

Use the result as <source-dir> (e.g. force-app/main/default) for all commands below.

Write both permission sets (React Experience Sites always need both):

  1. Read assets/MFA_Required_For_Community.permissionset-meta.xml
  2. Write it to <source-dir>/permissionsets/MFA_Required_For_Community.permissionset-meta.xml in the user's project
  3. Read assets/API_Enabled_For_Community.permissionset-meta.xml
  4. Write it to <source-dir>/permissionsets/API_Enabled_For_Community.permissionset-meta.xml
Step 3: Deploy to org
bash
sf project deploy start \
  --source-dir <source-dir>/permissionsets \
  --target-org <org-alias> --test-level NoTestRun
Step 3b: Validate community profile is a network member

Before assigning permission sets to users, verify that the community profile is registered as a site member. Without this, community users cannot log in at all (and MFA will never trigger).

  1. Query current network members:
bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, ParentId FROM NetworkMemberGroup WHERE NetworkId = '<NETWORK_ID>'" --json
  1. Check if the community profile is in the list:
bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Name FROM Profile WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess') AND Name LIKE '%Community%'" --json
  1. If the profile is NOT a member, add it to the .network-meta.xml:
xml
<networkMemberGroups>
    <!-- Replace with the community profile name from Step 3b query above -->
    <profile>YOUR_COMMUNITY_PROFILE_NAME</profile>
    <!-- existing entries -->
</networkMemberGroups>
  1. Deploy the updated network metadata:
bash
sf project deploy start \
  --source-dir <source-dir>/networks \
  --target-org <org-alias> --test-level NoTestRun

IMPORTANT: If the community profile is not a member of the network, users with that profile CANNOT log in — meaning MFA will never be triggered even if permission sets are correctly assigned. This is a common misconfiguration in freshly deployed orgs.

Step 3c: Validate guest profile has Apex class access for login

The site login page runs as the guest user (unauthenticated). If the guest profile doesn't have access to login Apex classes, users will get FORBIDDEN: You do not have access to the Apex class named: UIBundleLogin and can never reach the MFA challenge.

  1. Find the site guest user profile:
bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Username, Profile.Name, Profile.Id FROM User WHERE UserType = 'Guest' AND IsActive = true" --json
  1. Grant access to any missing UIBundle login classes. The six classes are UIBundleLogin, UIBundleAuthUtils, UIBundleForgotPassword, UIBundleChangePassword, UIBundleRegistration, and UIBundleSocialLoginConfig. Run the anonymous Apex in references/setup.md ("Grant Guest Profile Apex Class Access") — it diffs existing access and inserts only what's missing — or deploy <classAccess> entries for the same classes to the guest profile metadata XML.

IMPORTANT: This is NOT MFA-specific, but without it the login page itself is broken. The skill must validate this to ensure MFA can actually be triggered. Common in freshly deployed orgs where the guest profile didn't get full class access.

Step 4: Assign permission sets

Find community users:

bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Username, Name, Profile.Name FROM User WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess', 'CustomerSuccess') AND IsActive = true" --json
If community users exist:

Find the permission set IDs:

bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Name FROM PermissionSet WHERE Name IN ('MFA_Required_For_Community', 'API_Enabled_For_Community')" --json

Assign to each user:

bash
sf data create record --target-org <org-alias> --sobject PermissionSetAssignment \
  --values "AssigneeId='<USER_ID>' PermissionSetId='<PERM_SET_ID>'" --json

Alternatively, delegate to dx-org-permission-set-assign skill:

bash
sf org assign permset --name MFA_Required_For_Community --target-org <org-alias> --json
sf org assign permset --name API_Enabled_For_Community --target-org <org-alias> --json
If no community users found:

Ask the user: "No active community users found in this org. Would you like me to create a test community user so you can verify MFA is working?"

If user agrees, create a test community user:

  1. Find the community profile from the site's network configuration:
bash
sf data query --target-org <org-alias> \
  --query "SELECT Id, Name FROM Profile WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess') AND Name LIKE '%Customer Community%'" --json
  1. Create an Account (required as community user parent):
bash
sf data create record --target-org <org-alias> --sobject Account \
  --values "Name='MFA Test Account'" --json
  1. Create a Contact (linked to the Account):
bash
sf data create record --target-org <org-alias> --sobject Contact \
  --values "FirstName='MFA' LastName='Test User' Email='mfa.testuser@<site-name>.test' AccountId='<ACCOUNT_ID>'" --json
  1. Create the User with the community profile:
bash
sf data create record --target-org <org-alias> --sobject User \
  --values "FirstName='MFA' LastName='Test User' Email='mfa.testuser@<site-name>.test' Username='mfa.testuser@<site-name>.test' Alias='mfatest' ProfileId='<PROFILE_ID>' ContactId='<CONTACT_ID>' EmailEncodingKey='UTF-8' LanguageLocaleKey='en_US' LocaleSidKey='en_US' TimeZoneSidKey='America/Los_Angeles'" --json
  1. Set a password for the test user:
bash
sf data update record --target-org <org-alias> --sobject User \
  --where "Username='mfa.testuser@<site-name>.test'" \
  --values "IsActive=true" --json
bash
sf org generate password --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --json
  1. Assign both permission sets to the new user:
bash
sf org assign permset --name MFA_Required_For_Community --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --json
sf org assign permset --name API_Enabled_For_Community --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --json

Report the credentials to the user so they can test:

"Created test user: mfa.testuser@<site-name>.test with password: <generated-password>. You can use these credentials to verify MFA on your site."

IMPORTANT: Community users require Account → Contact → User hierarchy. Creating a User without a linked Contact on a community profile will fail.

Show full SKILL.md (748 more words)Show less
Step 5: Register the permission sets as site members (networkMemberGroups)

networkMemberGroups is a membership/access gate — it lists the profiles and permission sets whose holders count as members of the site. It does not assign MFA to users. Assignment happens in Step 4 (per user); register the sets here so assigned users still count as site members.

  1. Find the existing .network-meta.xml in the project:
bash
find . -name "*.network-meta.xml" -not -path "*/node_modules/*"
  1. Read the file and locate the <networkMemberGroups> section.

  2. Add the permission set entries (if not already present):

xml
<networkMemberGroups>
    <!-- Replace with the community profile name from Step 3b query -->
    <profile>YOUR_COMMUNITY_PROFILE_NAME</profile>
    <!-- Add MFA and API permission sets -->
    <permissionSet>MFA_Required_For_Community</permissionSet>
    <permissionSet>API_Enabled_For_Community</permissionSet>
</networkMemberGroups>

IMPORTANT: Network metadata deploys are declarative — whatever you deploy becomes the full state. Do NOT create a new .network-meta.xml from scratch. Always read the existing file and add entries to it.

  1. Deploy the updated network metadata:
bash
sf project deploy start \
  --source-dir <source-dir>/networks \
  --target-org <org-alias> --test-level NoTestRun
Step 6: Publish and verify
bash
sf community publish --name "<site-name>" --target-org <org-alias>

Verification steps:

  1. Open incognito browser
  2. Navigate to site login page
  3. Enter credentials → MFA challenge page should appear (on vforcesite domain)
  4. Complete MFA → should land on the site, logged in

Rules

RuleRationale
Never use the org-wide Identity Verification checkbox for community MFAIt only affects internal users — has no effect on community login
Always deploy ApiEnabled for React sitesPost-login API calls (sdk.graphql, sdk.fetch) will fail without it
Permission set names are exact — do not renameMFA_Required_For_Community and API_Enabled_For_Community are the canonical names
Do not build custom MFA UI componentsPlatform handles the entire MFA challenge flow — custom UI would duplicate and conflict
Always assign before testingDeployment alone does not activate MFA — assignment to specific users is required

Gotchas

SymptomCauseFix
No MFA challenge on loginForceTwoFactor permission not assigned to userVerify PermissionSetAssignment exists for the user
API_DISABLED_FOR_ORG after loginMissing ApiEnabled permissionAssign API_Enabled_For_Community permission set
MFA page shows default Salesforce brandingNo NetworkBranding metadata deployedRead references/branding.md and deploy custom branding
vforcesite in MFA page URLExpected behavior — not a bugPlatform serves login/MFA from Force.com Site domain
Identity Verification enabled but no community MFAWrong mechanism usedUse ForceTwoFactor via Permission Set instead
User already has MFA but isn't challengedActive session existsTest in incognito/private browser
Permission set deployed but MFA not enforcedDeployed but not assignedRun assignment step — deploy != assign
No community users found in orgUsers haven't been created or self-registered yetOffer to create a test community user (Account → Contact → User hierarchy) for verification. Permission sets are still deployed and networkMemberGroups updated — org is MFA-ready for when users exist.
New users aren't automatically protected by MFAnetworkMemberGroups only defines site membership — it does not assign permission sets to usersAssign MFA_Required_For_Community + API_Enabled_For_Community to each user that needs it (Step 4)
FORBIDDEN: You do not have access to the Apex class named: UIBundleLoginSite guest profile missing Apex class accessRun Step 3c to grant guest profile access to all UIBundle login classes
Community user can't log in (redirects silently or gets portal user email settings error)Community profile not a network member, or email deliverability not set to All EmailAdd profile to .network-meta.xml <networkMemberGroups> and redeploy (Step 3b). Verify email deliverability is set to "All Email" in Setup → Email → Deliverability.

Output Expectations

Files generated in the user's project:

FileWhen
permissionsets/MFA_Required_For_Community.permissionset-meta.xmlAlways
permissionsets/API_Enabled_For_Community.permissionset-meta.xmlAlways

When summarizing what was done, do NOT claim that adding permission sets to <networkMemberGroups> (or updating the network) causes new or self-registered users to automatically get MFA. It does not — networkMemberGroups only defines site membership. MFA is enforced only for users the permission set has been explicitly assigned to (Step 4). Report network changes as "registered the permission sets as site members," not as auto-assignment.


Cross-Skill Integration

WhenDelegate to
User only needs to assign (already deployed)dx-org-permission-set-assign
User needs to deploy all project metadataplatform-metadata-deploy
User wants to customize the login page UIexperience-ui-bundle-frontend-generate
User needs to create a new generic permission setplatform-permission-set-generate
User wants IDP/Social Login (different from MFA)Supported on React sites — the built-in Social Login component renders linked Auth Providers on the login page automatically. Create the Auth Providers in Setup, then link them to the React site via the experience-ui-bundle-deploy social login step (socialLogin in org-setup.config.json) — the React SSO admin UI is hidden, so linking is programmatic, not a Setup click-path. See references/social-login.md.

Reference File Index

FileWhen to read
assets/MFA_Required_For_Community.permissionset-meta.xmlStep 2 — writing permission set to project
assets/API_Enabled_For_Community.permissionset-meta.xmlStep 2 — always deployed
references/branding.mdWhen user wants to customize MFA/login page appearance
references/social-login.mdWhen user wants IDP/SSO/Social Login on a React site alongside or instead of MFA
references/setup.mdSteps 3–5 — detailed assignment, network membership, and publish reference

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references, assets) in skills/experience-ui-bundle-mfa-configure of forcedotcom/sf-skills.

  • SKILL.md
  • assets/API_Enabled_For_Community.permissionset-meta.xml
  • assets/MFA_Required_For_Community.permissionset-meta.xml
  • references/branding.md
  • references/setup.md
  • references/social-login.md

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Experience UI Bundle Mfa Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Experience UI Bundle Mfa Configure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Experience UI Bundle Mfa Configure this skillforcedotcom/sf-skills1.1k—~4.8kAutomated safety check: PassApache-2.0
Salesforce Enterprise Rbacjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Gh Bot Commentjetstreamapp/jetstream125—~616Automated safety check: PassCustom licence
Sf ApexJaganpro/sf-skills424—~2kAutomated safety check: PassMIT
Sf DebugJaganpro/sf-skills424—~1.3kAutomated safety check: PassMIT
Churn Riskindranilbanerjee/digital-marketing-pro8551 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Salesforce Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.

    2.8k GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Gh Bot Comment

    jetstreamapp/jetstream

    Post GitHub PR/issue comments, reviews, and review replies as the Jetstream bot account instead of the user's personal account.

    125 GitHub stars~616 tokensUpdated today
    DevelopmentAuto-check passed
  • Sf Apex

    Jaganpro/sf-skills

    Generates and reviews Salesforce Apex code with 150-point scoring.

    424 GitHub stars~2k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Sf Debug

    Jaganpro/sf-skills

    Salesforce debug log analysis and troubleshooting with 100-point scoring.

    424 GitHub stars~1.3k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Churn Risk

    indranilbanerjee/digital-marketing-pro

    Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…

    855 GitHub starsUsed in 1 repo~2.4k tokens
    Sales & SupportAuto-check passed
  • Lead Import

    indranilbanerjee/digital-marketing-pro

    Import leads into Salesforce, HubSpot, Zoho, or Pipedrive with validation, deduplication against existing CRM records, lead scoring, consent and compliance checks, and source attribution — then push…

    855 GitHub starsUsed in 1 repo~3.3k tokens
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Experience UI Bundle Mfa Configure

What does Experience UI Bundle Mfa Configure do?

Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users. Experience UI Bundle Mfa Configure is an agent skill from forcedotcom/sf-skills. Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.

When should I use Experience UI Bundle Mfa Configure?

Experience UI Bundle Mfa Configure fits situations like: : user wants to enable MFA on a community; enforce two-factor authentication for portal users; add MFA to a React Experience Site / Web App; configure ForceTwoFactor permission.

How do I install Experience UI Bundle Mfa Configure in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a claude-code`. Or copy the skill folder (skills/experience-ui-bundle-mfa-configure in forcedotcom/sf-skills) into .claude/skills/experience-ui-bundle-mfa-configure in your project. Claude Code loads it when a task matches its description.

How do I install Experience UI Bundle Mfa Configure in Codex?

Run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a codex`. Or copy the skill folder (skills/experience-ui-bundle-mfa-configure in forcedotcom/sf-skills) into .agents/skills/experience-ui-bundle-mfa-configure in your project. Codex loads it when a task matches its description.

Can I use Experience UI Bundle Mfa Configure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/experience-ui-bundle-mfa-configure, .gemini/skills/experience-ui-bundle-mfa-configure, .github/skills/experience-ui-bundle-mfa-configure and .opencode/skills/experience-ui-bundle-mfa-configure in your project.

What does Experience UI Bundle Mfa Configure need to run?

Going by SKILL.md and its folder, Experience UI Bundle Mfa Configure needs the command-line tools its instructions call (sf and jq).

Does Experience UI Bundle Mfa Configure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Experience UI Bundle Mfa Configure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Experience UI Bundle Mfa Configure use?

Experience UI Bundle Mfa Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Experience UI Bundle Mfa Configure use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Experience UI Bundle Mfa Configure?

Skills that share tags, products or a category with Experience UI Bundle Mfa Configure: Salesforce Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Gh Bot Comment (jetstreamapp/jetstream, 125 stars), Sf Apex (Jaganpro/sf-skills, 424 stars) and Sf Debug (Jaganpro/sf-skills, 424 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Experience UI Bundle Mfa Configure?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.