Agent skill

Platform Models API Configure

by forcedotcom in forcedotcom/sf-skills

Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT.

Apache-2.0Auto-check passedSales & Support

Install Platform Models API Configure

skills CLI
$ npx skills add forcedotcom/sf-skills --skill platform-models-api-configure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills platform-models-api-configure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-models-api-configure .claude/skills/platform-models-api-configure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-models-api-configure
GitHub stars
1.1k
Token cost
~2.1k tokens
SKILL.md length
743 words
Files
2 (incl. scripts)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT.

  • Works in 4 steps: Write /.claude/.orgjwt.env (chmod 600),… → Verify — must return 200 before writing… → Write .claude/settings.json (merge into… → …
  • Pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1)
  • SKILL.md covers Prerequisite, Inputs to collect, Steps (reference implementation) and Verify before finishing, plus 2 more sections
  • Runs Shell scripts from its folder; calls bash, curl and sf; reaches api.salesforce.com; needs ANTHROPIC_AUTH_TOKEN and SF_CLIENT_SECRET

What it does

Platform Models API Configure is an agent skill from forcedotcom/sf-skills. Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / "model not available" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/get-orgjwt.sh`).

It sits in Sales & Support, covering CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1)
  • Setting up OrgJWT / Bedrock-mode auth
  • Wiring the agents settings
  • Credentials file for the Salesforce endpoint

Example prompts

  • “model not available”
  • “/platform-models-api-configure”

Requirements

  • A Bash shell
  • A credential in SF_CLIENT_SECRET
  • A credential in ANTHROPIC_AUTH_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Write /.claude/.orgjwt.env (chmod 600), gitignore it
  2. Verify — must return 200 before writing settings
  3. Write .claude/settings.json (merge into existing; keep other keys)
  4. Tell the admin to fully restart the agent (claude for the reference agent) —

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • curl
    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.salesforce.com

    Also links to:

    • developer.salesforce.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_AUTH_TOKEN
    • SF_CLIENT_SECRET
    • ANTHROPIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Models API Configure loads about 2.1k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 743 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 743 words, ~2,095 tokens.

Download SKILL.mdSave it as .claude/skills/platform-models-api-configure/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
platform-models-api-configure
description
Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / "model not available" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use integration-connectivity-connected-app-configure) or set up Named Credentials / callout auth (use integration-connectivity-generate).
metadata.version
1.0
metadata.domains
Platform, Agentforce
metadata.relatedSkills
integration-connectivity-connected-app-configure, integration-connectivity-generate

Salesforce Models API setup for an AI coding agent

The Salesforce Models API (https://api.salesforce.com/ai/gpt/v1) is authenticated with a signed OrgJWT (obtained via client_credentials with the sfap_api scope — see scripts/get-orgjwt.sh; no proxy). That auth and the base URL are the same for any agent. How each agent then talks to the endpoint is agent-specific: Anthropic clients (Claude Code and the Claude Agent SDK) route through Bedrock mode (the env vars in Step 3), whereas other agents (e.g. Codex) use their own client config against the same endpoint and token — Bedrock mode does not apply to them.

The steps below are the Claude Code / Claude Agent SDK reference implementation (Bedrock mode + a JSON settings file + an API-key helper). For a non-Bedrock agent, reuse the OrgJWT auth (Step 1) and the base URL, and apply the equivalent client settings in that agent's own config location instead of the Bedrock env vars.

Bundled scripts are in scripts/. Path placeholders below: <SKILL> = the absolute path to this skill's own directory (the folder containing this SKILL.md; resolve it from the skill path in context). <ABS> = the absolute path to the user's project root. Always emit fully resolved absolute paths — the API-key helper runs from an undefined working directory, so relative paths break it.

Prerequisite

A connected app in the org with the sfap_api OAuth scope and the client_credentials flow enabled (consumer key/secret + a run-as user). Setup steps: https://developer.salesforce.com/docs/ai/agentforce/guide/access-models-api-with-rest.html curl + jq installed.

Inputs to collect

  • SF_INSTANCE_URL — org My Domain, e.g. https://acme.my.salesforce.com
  • SF_CLIENT_ID, SF_CLIENT_SECRET — connected-app consumer key/secret
  • Models API base URL: https://api.salesforce.com/ai/gpt/v1
  • Model: a fully qualified sfdc_ai__… name, e.g. sfdc_ai__DefaultBedrockAnthropicClaude46Sonnet (full list: https://developer.salesforce.com/docs/ai/agentforce/guide/supported-models.html)
  • Scope: project (<cwd>/.claude/settings.json, default) or user (~/.claude/settings.json) — reference-agent settings paths
  • Headers — <FEAT> = x-client-feature-id (default ai-platform-models-connected-app), <APP> = x-sfdc-app-context (default EinsteinGPT). Used in the Step 2 verify curl and in ANTHROPIC_CUSTOM_HEADERS.

Steps (reference implementation)

Concrete values for a JSON-settings + API-key-helper agent. Reuse the OrgJWT auth, verify curl, and base URL verbatim for any agent; adapt the settings-file location and env-var wiring to the target agent.

  1. Write <project>/.claude/.orgjwt.env (chmod 600), gitignore it:
    ini
    SF_INSTANCE_URL="..."
    SF_CLIENT_ID="..."
    SF_CLIENT_SECRET="..."
  2. Verify — must return 200 before writing settings:
    bash
    TOKEN=$(bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env)
    curl -s -o /dev/null -w '%{http_code}\n' \
      <MODELS_API_URL>/model/<MODEL>/invoke-with-response-stream \
      -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
      -H 'x-client-feature-id: <FEAT>' -H 'x-sfdc-app-context: <APP>' \
      --data '{"anthropic_version":"bedrock-2023-05-31","max_tokens":16,"messages":[{"role":"user","content":"hi"}]}'
  3. Write .claude/settings.json (merge into existing; keep other keys):
    json
    {
      "apiKeyHelper": "bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env",
      "model": "<MODEL>",
      "env": {
        "ANTHROPIC_AUTH_TOKEN": "",
        "CLAUDE_CODE_USE_BEDROCK": "1",
        "CLAUDE_CODE_SKIP_BEDROCK_AUTH": "1",
        "ANTHROPIC_BEDROCK_BASE_URL": "<MODELS_API_URL>",
        "ANTHROPIC_SMALL_FAST_MODEL": "<MODEL>",
        "ANTHROPIC_DEFAULT_MODEL": "<MODEL>",
        "ANTHROPIC_CUSTOM_HEADERS": "x-client-feature-id: <FEAT>\nx-sfdc-app-context: <APP>"
      }
    }
    Use absolute paths in apiKeyHelper. (<FEAT> / <APP> defaults are in "Inputs to collect" above.)
  4. Tell the admin to fully restart the agent (claude for the reference agent) — settings and the API-key helper load at startup only.
Show full SKILL.md (354 more words)Show less
Capturing as a runbook (when asked to document, not apply)

If the user wants the setup written up for review instead of applied to their machine (e.g. "save it as a Markdown runbook"), write all of the above into the requested file (e.g. models-api-setup-runbook.md), in order and self-contained: the exact .orgjwt.env contents, the chmod 600 + gitignore note, the verification curl (with the "must be 200 before writing settings" note), the full settings.json block with every key from Step 3, and the final "fully restart claude" step. Don't omit any of the nine settings.json keys.

Verify before finishing

  • .claude/.orgjwt.env created, chmod 600, and gitignored
  • Verification curl returned HTTP 200 before settings.json was written
  • ANTHROPIC_AUTH_TOKEN set to "" in settings.json
  • CLAUDE_CODE_USE_BEDROCK set to "1"
  • CLAUDE_CODE_SKIP_BEDROCK_AUTH set to "1"
  • ANTHROPIC_BEDROCK_BASE_URL is exactly https://api.salesforce.com/ai/gpt/v1 (no trailing slash/path)
  • model, ANTHROPIC_DEFAULT_MODEL, and ANTHROPIC_SMALL_FAST_MODEL all use the fully qualified sfdc_ai__… alias
  • ANTHROPIC_CUSTOM_HEADERS contains x-client-feature-id and x-sfdc-app-context
  • apiKeyHelper uses absolute paths (bash <SKILL>/scripts/get-orgjwt.sh <ABS>/.claude/.orgjwt.env)
  • User told to fully restart claude

Must be exact (each prevents a specific failure)

  • "ANTHROPIC_AUTH_TOKEN": "" — clears any global token that would otherwise outrank apiKeyHelper (precedence: ANTHROPIC_AUTH_TOKEN > ANTHROPIC_API_KEY

    apiKeyHelper). Without it → wrong/old bearer → 401/404.

  • CLAUDE_CODE_USE_BEDROCK=1 — activates the Bedrock API client; without it Claude Code uses the standard Anthropic API protocol and ignores ANTHROPIC_BEDROCK_BASE_URL entirely, so every call bypasses the Models API.
  • CLAUDE_CODE_SKIP_BEDROCK_AUTH=1 — else Claude Code overwrites Authorization with AWS SigV4 and the OrgJWT never lands.
  • apiKeyHelper must be invoked as bash <path> <credsfile> (avoids exit-126).
  • Model must be a fully qualified sfdc_ai__… name (see supported models).
  • Auth is the OrgJWT from client_credentials (a signed JWT, 2 dots, scope sfap_api) — NOT sf org display (unsigned session token → 404). sf CLI has no client_credentials command; the helper calls /services/oauth2/token.
  • Only ANTHROPIC_BEDROCK_BASE_URL routes; no tenant-id header needed.

Diagnose

ErrorMeaningCheck first
401Token is not a valid OrgJWTConnected App sfap_api scope, client_credentials flow enabled, consumer key/secret in .orgjwt.env; ANTHROPIC_AUTH_TOKEN not cleared to ""
404Token valid but model/env/org not routableFully qualified sfdc_ai__… model alias, ANTHROPIC_BEDROCK_BASE_URL exactly https://api.salesforce.com/ai/gpt/v1, org entitled for the Models API, ANTHROPIC_AUTH_TOKEN cleared
model not availableNon-alias model idReplace with a fully qualified sfdc_ai__… alias (see supported models)

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/platform-models-api-configure of forcedotcom/sf-skills.

  • SKILL.md
  • scripts/get-orgjwt.sh

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Platform Models API Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Models API Configure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Models API Configure this skillforcedotcom/sf-skills1.1k—~2.1kAutomated safety check: PassApache-2.0
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT
Dev SetupPortwood-Global-Solutions/Portwood125—~1.1kAutomated safety check: PassApache-2.0
Sf FlowJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 4 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 4 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    125 GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated today
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated today
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Platform Models API Configure

What does Platform Models API Configure do?

Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Platform Models API Configure is an agent skill from forcedotcom/sf-skills. Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT.

When should I use Platform Models API Configure?

Platform Models API Configure fits situations like: pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1); setting up OrgJWT / Bedrock-mode auth; wiring the agents settings; credentials file for the Salesforce endpoint.

How do I install Platform Models API Configure in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill platform-models-api-configure -a claude-code`. Or copy the skill folder (skills/platform-models-api-configure in forcedotcom/sf-skills) into .claude/skills/platform-models-api-configure in your project. Claude Code loads it when a task matches its description.

How do I install Platform Models API Configure in Codex?

Run `npx skills add forcedotcom/sf-skills --skill platform-models-api-configure -a codex`. Or copy the skill folder (skills/platform-models-api-configure in forcedotcom/sf-skills) into .agents/skills/platform-models-api-configure in your project. Codex loads it when a task matches its description.

Can I use Platform Models API Configure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-models-api-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-models-api-configure, .gemini/skills/platform-models-api-configure, .github/skills/platform-models-api-configure and .opencode/skills/platform-models-api-configure in your project.

What does Platform Models API Configure need to run?

Going by SKILL.md and its folder, Platform Models API Configure needs a shell for the scripts in its folder, the command-line tools its instructions call (bash, curl and sf) and credentials named ANTHROPIC_AUTH_TOKEN, SF_CLIENT_SECRET and ANTHROPIC_API_KEY. Our summary lists: A Bash shell; A credential in SF_CLIENT_SECRET; A credential in ANTHROPIC_AUTH_TOKEN.

Does Platform Models API Configure access the network?

SKILL.md names 2 domains. In commands or code: api.salesforce.com; the agent is likely to contact it when it follows the instructions. As links in the text: developer.salesforce.com. This is read from the text; nothing was executed.

Is Platform Models API Configure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Platform Models API Configure use?

Platform Models API Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Platform Models API Configure use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Platform Models API Configure?

Skills that share tags, products or a category with Platform Models API Configure: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Models API Configure?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.