platform-models-api-configure

Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key h

By forcedotcom · 3,936 installs

npx skills add forcedotcom/sf-skills --skill platform-models-api-configure

Source repository · Upstream listing

Salesforce Models API setup for an AI coding agent The Salesforce Models API ( https://api.salesforce.com/ai/gpt/v1 ) is authenticated with a signed OrgJWT (obtained via client credentials with the sfap api scope — see scripts/get orgjwt.sh ; no proxy). That auth and the base URL are the same for any agent. How each agent then talks to the endpoint is agent specific: Anthropic clients ( Claude Code and the Claude Agent SDK ) route through Bedrock mode (the env vars in Step 3), whereas other agents (e.g. Codex) use their own client config against the same endpoint and token — Bedrock mode does not apply to them. The steps below are the Claude Code / Claude Agent SDK reference implementation (Bedrock mode + a JSON settings file + an API key helper). For a non Bedrock agent, reuse the OrgJWT auth (Step 1) and the base URL, and apply the equivalent client settings in that agent's own config location instead of the Bedrock env vars. Bundled scripts are in scripts/ . Path placeholders below: <SKILL = the absolute path to this skill's own directory (the folder containing this SKILL.md ; resolve it from the skill path in context). <ABS = the absolute path to the user's project root. Always emit fully resolved absolute paths — the API key helper runs from an undefined working directory, so relative paths break it. Prerequisite A connected app in the org with the sfap api OAuth scope and the client credentials flow enabled (consumer key/secret + a run as user). Setup steps: https://developer.salesforce.com/docs/ai/agentforce/guide/access models api with rest.html curl + jq installed. Inputs to collect SF INSTANCE URL — org My Domain, e.g. https://acme.my.salesforce.com SF CLIENT ID , SF CLIENT SECRET — connected app consumer key/secret Models API base URL: https://api.salesforce.com/ai/gpt/v1 Model: a fully qualified sfdc ai … name, e.g. sfdc ai DefaultBedrockAnthropicClaude46Sonnet (full list: https://developer.salesforce.com/docs/ai/agentforce/guide/supported models.html) Scope: project ( <cwd /.claude/settings.json , default) or user ( ~/.claude/settings.json ) — reference agent settings paths Headers — <FEAT = x client feature id (default ai platform models connected app ), <APP = x sfdc app context (default EinsteinGPT ). Used in the Step 2 verify curl and in ANTHROPIC CUSTOM HEADERS . Steps (reference implementation) Concrete values for a JSON settings + API key helper agent. Reuse the OrgJWT auth, verify curl, and base URL verbatim for any agent; adapt the settings file location and env var wiring to the target agent. 1. Write <project /.claude/.orgjwt.env (chmod 600), gitignore it: 2. Verify — must return 200 before writing settings: 3. Write .claude/settings.json (merge into existing; keep other keys): Use absolute paths in apiKeyHelper . ( <FEAT / <APP defaults are in "Inputs to collect" above.) 4. Tell the admin to fully restart the agent ( claude for the reference agent) — settings and the API key helper load at startup only. Capturing as a runbook (when asked to document, not apply) If the user wants the setup written up for review instead of applied to their machine (e.g. "save it as a Markdown runbook"), write all of the above into the requested file (e.g. models api setup runbook.md ), in order and self contained: the exact .orgjwt.env contents, the chmod 600 + gitignore note, the verification curl (with the "must be 200 before writing settings" note), the full settings.json block with every key from Step 3, and the final "fully restart claude " step. Don't omit any of the nine settings.json keys. Verify before finishing [ ] .claude/.orgjwt.env created, chmod 600 , and gitignored [ ] Verification curl returned HTTP 200 before settings.json was written [ ] ANTHROPIC AUTH TOKEN set to "" in settings.json [ ] CLAUDE CODE USE BEDROCK set to "1" [ ] CLAUDE CODE SKIP BEDROCK AUTH set to "1" [ ] ANTHROPIC BEDROCK BASE URL is exactly https://api.salesforce.com/ai/gpt/v1 (no trailing slash/path) [ ] model , ANTHROPIC DEFAULT MODEL , and ANTHROPIC SMALL FAST MODEL all use the fully qualified sfdc ai … alias [ ] ANTHROPIC CUSTOM HEADERS contains x client feature id and x sfdc app context [ ] apiKeyHelper uses absolute paths ( bash <SKILL /scripts/get orgjwt.sh <ABS /.claude/.orgjwt.env ) [ ] User told to fully restart claude Must be exact (each prevents a specific failure) "ANTHROPIC AUTH TOKEN": "" — clears any global token that would otherwise outrank apiKeyHelper (precedence: ANTHROPIC AUTH TOKEN ANTHROPIC API KEY apiKeyHelper ). Without it → wrong/old bearer → 401/404. CLAUDE CODE USE BEDROCK=1 — activates the Bedrock API client; without it Claude Code uses the standard Anthropic API protocol and ignores ANTHROPIC BEDROCK BASE URL entirely, so every call bypasses the Models API. CLAUDE CODE SKIP BEDROCK AUTH=1 — else Claude Code overwrites Authorization with AWS SigV4 and the OrgJWT never lands. apiKeyHelper must be invoked as bash <path <credsfile (avoids exit 126). Model must be a fully qualified sfdc ai … name (see supported models). Auth is the OrgJWT from client credentials (a signed JWT, 2 dots, scope sfap api ) — NOT sf org display (unsigned session token → 404). sf CLI has no client credentials command; the helper calls /services/oauth2/token . Only ANTHROPIC BEDROCK BASE URL routes; no tenant id header needed. Diagnose Error Meaning Check first 401 Token is not a valid OrgJWT Connected App sfap api scope, client credentials flow enabled, consumer key/secret in .orgjwt.env ; ANTHROPIC AUTH TOKEN not cleared to "" 404 Token valid but model/env/org not routable Fully qualified sfdc ai … model alias, ANTHROPIC BEDROCK BASE URL exactly https://api.salesforce.com/ai/gpt/v1 , org entitled for the Models API, ANTHROPIC AUTH TOKEN cleared model not available Non alias model id Replace with a fully qualified sfdc ai … alias (see supported models)