SyncOnAI360

Cursor connector

Write Salesforce code in Cursor with the org in view.

Cursor sees your project files. Connected to SyncOnAI 360, it also sees the org: the real fields, the Flows on an object and everything that depends on the class you are editing.

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

In one paragraph

The SyncOnAI 360 Cursor connector gives Cursor read-only access to your connected Salesforce orgs through a Model Context Protocol server. Cursor can search the org's metadata, look up any component and what depends on it, and read health findings, so the code it writes uses real API names and accounts for what else will be affected.

Config block in .cursor/mcp.json
1Config block in .cursor/mcp.json
Write actions available to Cursor
0Write actions available to Cursor
Call logged with its tool and token
EveryCall logged with its tool and token
Token scope you choose
Per orgToken scope you choose

01The problem

Why AI code for Salesforce misses the org

A project folder holds the code a developer is working on, but rarely the whole org. Cursor writes Apex and components against what it can see, and the org it cannot see is where the surprises are.

  1. 01

    Fields that do not exist

    Generated code references API names that are close to right and fail at deploy.

  2. 02

    Invisible automation

    A trigger is written without knowing the Flows and validation rules that run on the same save.

  3. 03

    Unknown dependents

    Changing a method signature breaks components and classes outside the open project.

  4. 04

    Partial retrieves

    Keeping a full, current copy of the org in the project is slow and goes stale.

02context

What does Cursor learn about the org?

Through the connector, Cursor can search the org's metadata, look up a component and everything that depends on it, list the orgs its token may see and read the findings of a health assessment. It works from SyncOnAI 360's synced copy of the org, which includes the full source of Apex, Flows and Lightning Web Components.

Ask Cursor what runs when a Case is saved before writing a trigger, or what calls a method before changing its signature, and it answers from the org rather than from the open files alone.

  • Org-wide metadata search
  • Dependencies for any component
  • Health findings for context

Lineage: Case.Priority

Acme Production · what uses it, what it uses

03coverage

Can Cursor trust a negative answer?

Every answer says how much of the org it was based on. If a search hit its limit or the token can see only some orgs, Cursor is told, so nothing references this method means what it says or is flagged as incomplete.

Where source could not be read, such as managed package code hidden by its publisher, that is reported rather than treated as proof that nothing depends on it.

  • Coverage stated with answers
  • Hidden package source reported
  • No silent gaps

Lineage: Case.Priority

Acme Production · what uses it, what it uses

04setup

How do you connect Cursor to Salesforce?

Create an access token in SyncOnAI 360 under Settings, then Integrations, choose the orgs it may read, and copy it immediately. Add the server address and the token as a bearer header to .cursor/mcp.json in your project, or to the file in your home folder to use it everywhere.

Ask Cursor which Salesforce orgs it can see to check the connection, then ask something real about the code in front of you.

  • One token per machine
  • Project or global config
  • Check with a first question

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

05ship

How does code from Cursor reach the org?

The connector is read-only: Cursor cannot deploy, edit or delete anything in an org. Code goes to the org through your normal route, or through SyncOnAI 360, where it becomes a proposal with named checks, its blast radius and a test coverage check, validated against the org before anyone approves.

Apex Logic in SyncOnAI 360 refuses edits that would not compile, and a component can be proposed together with its Apex controller and its test as one change.

  • Read-only by design
  • Proposals with coverage checks
  • Component, controller and test together

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

06control

How is Cursor's access controlled?

Tokens are scoped to the orgs you choose and revoked instantly in Settings. Every call is written to the activity log with the tool and token it used, and each token shows when it was last used; arguments are not recorded.

A token is a password: anyone holding it can read the orgs it is scoped to. Keep one per machine and prefer narrow scopes.

  • Scoped and revocable
  • Every call logged
  • One token per machine

Workspace security

Settings · Security

  • Configuration onlyMetadata and code. CRM records stay in Salesforce.
  • Isolated per customerEnforced by the database and tested every release.
  • Keys in Google Cloud KMSCredentials encrypted under a per-customer key.
  • Second admin for productionThe author can never approve their own change.
  • Hosted in the United StatesEvery subprocessor listed with its region.

07How it works

Connecting Cursor

From token to an org-aware editor.

  1. 01

    Create a token

    Scope it to the orgs this project touches.

  2. 02

    Add the server

    One block in .cursor/mcp.json.

  3. 03

    Ask

    What runs on this object? What calls this method?

  4. 04

    Ship safely

    Propose the change through checks and approval.

08Before and after

Salesforce code in Cursor, with and without the org

Without

With SyncOnAI 360

Close-enough field names

Real API names from the org

Triggers written blind to Flows

Automation on the object in view

Signature changes that break callers

Dependents looked up first

A stale partial retrieve

A synced copy refreshed every six hours

AI with deploy rights

Read-only, scoped, logged access

10Questions

Frequently asked questions

No. The connector is read-only. Deploy through your normal route, or propose the change in SyncOnAI 360.

In .cursor/mcp.json in your project, or in the same file in your home folder to use it in every project.

No. SyncOnAI 360 keeps metadata, not CRM records, and the connector reads only metadata and findings.

For answering questions about the org, yes. You still keep the code you are editing in your project as usual.

The synced copy refreshes every six hours, on demand, and straight after deploys made through SyncOnAI 360.

Yes. Scope the token to the sandbox org only.

Yes, with the tool and token used. The arguments are not recorded.

Any client that speaks Model Context Protocol over HTTP can connect the same way.

Yes. Every plan includes every feature.

They can, but one token per machine is better: revoking a lost laptop's token then disturbs nobody else, and the log shows which machine made each call.

Yes. Flows are part of the synced metadata with their full definition, so Cursor can ask what runs on an object before writing code.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI