YOUR FIRST FLIGHT
Get your head
in the cloud.
Connect the Salesforce orgs you manage. Give your agent the right context. Keep the final say on user creation and access changes.
Headful Cloud is in invitation-only beta. Join the launch list for access. The plugin package is available for private testing; public ChatGPT directory approval is a separate step.
1. Sign in to your workspace
Open Headful Cloud Setup and use your invited email address. Follow the emailed link, or enter the six-digit code, in the same browser that requested it. Your workspace brings your applications, orgs, users and access setup, leads, permission sets, and agent connections together.
2. Create your Salesforce OAuth app
Headful Cloud provides the MCP your chat uses. You configure a Salesforce OAuth application; there is no Salesforce MCP server to create or deploy.
For a new integration, create an External Client App in Salesforce Setup. An existing Connected App works too. Salesforce now restricts new Connected App creation, so the External Client App path is the current starting point. Salesforce setup guidance ↗
- In Salesforce Setup → App Manager, choose New External Client App, give it a name, and enable OAuth.
- Set this exact callback:
https://headful.cloud/oauth/salesforce/callback - Select API access (
api), refresh access (refresh_token, shown withoffline_access), and identity URL access (id). - Use the authorization-code/web server flow. Require PKCE and the client secret for the web server flow. Configure permitted users according to your org's policy.
- Save the app and obtain its Consumer Key and Consumer Secret from OAuth settings. Keep the secret out of chat.
Salesforce's OAuth settings reference ↗
3. Connect production. Find your sandboxes.
In Headful Cloud Setup, save an application with its key, secret, and login origin. Use https://login.salesforce.com for production, https://test.salesforce.com for a sandbox, or your actual Salesforce My Domain origin.
Choose Connect org, name your production connection, and authorize it in Salesforce. Then open its sandbox inventory to see the bounded list visible to that Salesforce user. Select a sandbox to start a separate connection using its own login and consent. Save or select an OAuth application configured for that sandbox; production credentials are not assumed to work everywhere. Repeat for each org you manage. Your credentials and Salesforce tokens are encrypted at rest; Salesforce decides what the connected user can read and change.
4. Bring your orgs into chat
The Agent Plugin bundles an authenticated MCP connection with four skills: Salesforce admin, user creation and access setup, lead review, and permission-set review.
Extract the ZIP into a local folder. It includes a portable plugin manifest and a local marketplace. In a supported Codex CLI, add the extracted directory:
codex plugin marketplace add /absolute/path/to/extracted-headful-cloudRestart your supported desktop client, open its Plugins Directory, select the Headful Cloud local source, and install. Local marketplace support depends on your client and workspace policy.
For a direct ChatGPT connection, enable developer mode where your account supports it, then add this MCP URL with OAuth authentication:
https://headful.cloud/mcpSign in to Headful Cloud and choose the orgs this agent may use. Read access, draft/proposal preparation, user creation, access assignments, and permission-set definition edits have separate operation scopes. Connecting a plugin does not approve any particular write. An org added later needs a new agent consent before it appears in chat.
To combine the downloaded skills with a registered ChatGPT MCP connection in a supported local Work/desktop plugin, copy the connection's actual technical ID beginning plugin_asdk_app. Give that ID and the extracted plugin folder to @plugin-creator in Work mode (or $plugin-creator in Codex), requesting the registered MCP mapping and a personal marketplace entry. Review the generated mapping before installing. The ZIP's INSTALL.md has the details. Official OpenAI installation guidance ↗
A direct MCP connection supplies tools and Apps; bundled skills require a plugin install. ZIP upload is not available on every ChatGPT surface. Headful Cloud does not claim public directory listing or native-host acceptance before those have been completed.
From a compact form to a detailed workspace
Start user creation in a compact App. Review its exact fields and explicitly Create. After Salesforce confirms the new user, the result says User created. Access setup is pending. Continue access setup keeps the same org, user, draft revision, and workflow. The detailed workspace supports permission-set additions/removals, definition reviews, and lead records.
Headful declares a conversation workspace entrypoint for supported ChatGPT clients. Continue requests fullscreen when supported and retains the useful current App if the host declines. You can manually open the conversation entrypoint and select the retained workflow. ChatGPT chooses presentation; a local preview does not establish native acceptance. Ordinary account Setup remains available without a custom browser handoff.
5. Start with something useful
- “List my Salesforce orgs and let me choose one.”
- “List the sandboxes visible from my production org.”
- “Help me create a user for Maya Chen in my connected UAT sandbox.”
- “Continue access setup for the user we created.”
- “Show the unconverted leads in my UAT sandbox.”
- “Review this custom permission set and prepare a change to Lead read access.”
Lead viewing is read-only. User creation and permission changes stay drafts or proposals until you review and explicitly approve the exact operation in the authenticated App or Setup. The service rechecks Salesforce state and verifies the result. If a write outcome is uncertain, use the saved workflow for supported reconciliation or inspect the org directly before preparing another change.
Claude remote connection
Where your Claude account and workspace allow custom remote connectors, add https://headful.cloud/mcp with OAuth sign-in. Use automatic client registration when offered, then consent to the selected orgs and operations. Organization owners may need to add the connector first. This MCP connection does not install the OpenAI-format skills package or prove Headful UI acceptance in Claude. Official Claude connection guidance ↗
You hold the controls
Revoke an agent connection in Setup or disconnect an org at any time. Disconnecting clears that connection's stored tokens; revoke the application in Salesforce's OAuth usage controls as well when you need to end provider-side access.