SFCC DevBLOCK
Supercharge your Salesforce B2C Commerce Cloud development with AI-powered documentation access, real-time log analysis, and intelligent best practices guidance
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/sfcc-dev-mcp) [](https://opensource.org/licenses/MIT)
An AI-powered Model Context Protocol (MCP) server that provides comprehensive access to Salesforce B2C Commerce Cloud development tools, documentation, and runtime diagnostics.
✨ Key Features
- 🔍 Complete SFCC Documentation Access - Search and explore all SFCC API classes and methods
- 🏗️ SFRA Documentation - Enhanced access to Storefront Reference Architecture documentation
- 🧱 ISML Template Reference - Complete ISML element documentation with examples and usage guidance
- 📊 Log Analysis Tools - Real-time error monitoring, debugging, and job log analysis for SFCC instances
- ⚙️ System Object Definitions - Explore custom attributes and site preferences
- 🧪 Script Debugger - Execute and inspect script-debugger endpoints in credentialed mode, including custom trigger URLs/paths for non-default storefront routes
- 🚀 Cartridge Generation - Automated cartridge structure creation with workspace-bound path safety (writes stay inside workspace roots, or current working directory fallback when roots are unavailable; home-directory fallback is blocked)
- 🧩 Agent Skill Bootstrap - Install or merge AGENTS.md and bundled skills into the current project or a temp directory for AI assistants
- ✅ Tool Argument Validation - Runtime schema validation enforces required fields, type checks, enum constraints, integer/numeric bounds, and strict unknown-key checks for object schemas (top-level and nested) before handler execution
- ⏱️ MCP Progress + Cancellation - Tool calls honor request cancellation signals and emit out-of-band
notifications/progressupdates when clients provide aprogressToken
🚀 Quick Start
Option 1: Documentation-Only Mode (No SFCC credentials needed)
{
"mcpServers":37d925b6f7d6OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sfcc-dev-mcp -- npx -y [email protected]
Exposed tools (62)
59 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
activate_code_version | read | Activate a code version (deactivates current). Use for code-switch fixes, SCAPI endpoint issues, or deployment conflicts. Only inactive versions can be activated. |
disable_agent_sync | write | Creates or updates mcp-dev.json in the project root with { |
fallback | read | fallback element |
generate_cartridge_structure | read | Generate a complete SFCC cartridge with proper directory structure, configurations, and boilerplate files. Creates files directly in the target directory. |
get_available_sfra_documents | read | List all SFRA documentation including Server, Request, Response, QueryString, render module, and 26+ model docs (cart, account, billing, shipping, products, pricing). |
get_code_versions | read | List all code versions on the SFCC instance. Use for deployment management, identifying active version, or preparing code-switch fixes. |
get_isml_categories | read | Get all ISML element categories with descriptions and counts. |
get_isml_element | read | Get detailed documentation for an ISML element including syntax, attributes, examples, and use cases. |
get_isml_elements_by_category | read | Get ISML elements filtered by category (control-flow, output, includes, scripting, cache, decorators, special, payment, analytics). |
get_job_execution_summary | read | Get execution summary for a job: timing, status, error counts, and step info. Use for monitoring job health and performance. |
get_job_log_entries | read | Get job log entries by level (error/warn/info/debug/all). Unlike standard logs, job logs combine all levels in one file. |
get_latest_job_log_files | read | Get recent job log files from /Logs/jobs/. Job logs contain all log levels in single files. Use for debugging custom job steps. |
get_log_file_contents | read | Read full contents of a specific log file. Use for detailed analysis when you need complete error traces or full context. |
get_sfcc_class_documentation | read | Get the full raw documentation for an SFCC class including examples and detailed descriptions. Use when get_sfcc_class_info lacks sufficient detail. |
get_sfcc_class_info | read | Get detailed information about an SFCC class including properties, methods, constants, and inheritance. Essential for understanding dw.* APIs when building controllers, scripts, templates, or REST APIs. Supports filtering by section and search within class members. |
get_sfra_categories | read | Get all SFRA document categories with counts. Use to understand documentation organization before browsing. |
get_sfra_document | read | Get complete SFRA class or model documentation with properties, methods, and examples. Use for implementing controllers, middleware, or working with SFRA models. |
get_sfra_documents_by_category | read | Get SFRA documents filtered by functional area (core classes, product models, order/cart, customer, pricing, store). |
get_system_object_definition | read | Get metadata for a specific system object (attribute count, group count, flags). For attribute details, use search_system_object_attribute_definitions. Does not work for Custom Objects. |
get_system_object_definitions | read | Get all system object definitions with metadata (not attributes). Use to discover available objects and identify Custom Objects via the _type field. |
isif | read | Conditional element |
isloop | read | Loop element |
isprint | read | Output element |
list_isml_elements | read | List all ISML template elements with summaries. Includes control flow (isif, isloop), output (isprint), includes (isinclude, iscomponent), scripting (isscript), and caching (iscache). |
list_log_files | read | List available log files with sizes and modification dates. Use to discover available log data or check log retention. |
list_sfcc_classes | read | List all available SFCC dw.* classes organized by namespace. Use to explore the full API surface or find classes in a specific domain. |
search_custom_object_attribute_definitions | read | Search attribute definitions within a custom object type (user-defined objects, not system objects). Supports text search, filtering, and sorting. |
search_isml_elements | read | Search ISML elements by purpose, attribute name, or use case. Returns relevance-scored results with preview snippets. |
search_job_logs | read | Search job logs for patterns, error messages, or custom logging from job steps. Essential for debugging custom job code. |
search_job_logs_by_name | read | Find job log files by job name (partial match supported). Use to locate logs for a specific job. |
search_logs | write | Search logs for specific patterns, error messages, order numbers, user IDs, or custom identifiers. Essential for tracking specific transactions. |
search_sfcc_classes | read | Find SFCC classes by partial name or keyword. Use when you don |
search_sfcc_methods | read | Find methods across all dw.* classes by name. Use when you know a method exists but not which class contains it. |
search_sfra_documentation | read | Search across all SFRA docs for concepts or functionality. Returns relevance-scored results with categorization. |
search_site_preferences | read | Search site preferences by name, description, or type. Use to validate preference names and types when working with Site.getCurrent().getCustomPreferenceValue() or dw.system.Site.current.preferences.custom.*. |
search_system_object_attribute_definitions | read | Search attribute definitions within a system object. Supports text search, filtering by mandatory/searchable/system, and sorting. Use match_all_query to get all attributes. |
search_system_object_attribute_groups | read | Search attribute groups for a system object. Use |
sfcc-caching | read | Unified caching playbook for SFCC (page cache vs custom cache vs service response cache). Use this when improving performance, reducing external calls, designing cache keys/TTLs, or debugging stale cache behavior. |
sfcc-cartridge-development | read | Guide for creating, configuring, and deploying custom SFRA cartridges in Salesforce B2C Commerce. Use this when asked to create a new cartridge, set up a cartridge structure, or work with cartridge paths. |
sfcc-forms-development | read | Guide for building, validating, securing, and persisting SFCC storefront forms (SFRA + SiteGenesis patterns). Use this when creating or troubleshooting form XML, controller handling, CSRF, and validation. |
sfcc-fraud-prevention | read | Layered fraud prevention playbook for Salesforce B2C Commerce developers. Use this when adding fraud signals, designing a risk scoring approach, integrating third-party tools, or hardening checkout/login against bot-driven abuse. |
sfcc-hooks-registration | read | Register SFCC hooks via cartridge package.json and hooks.json. Use when adding hooks or troubleshooting hook registration. |
sfcc-isml-development | read | SFRA-first guide for developing ISML templates in Salesforce B2C Commerce (Bootstrap 4 conventions). Use this when creating, modifying, or troubleshooting SFRA templates, decorators, components, forms, includes, and caching. |
sfcc-job-development | read | Guide for developing custom jobs in Salesforce B2C Commerce Job Framework. Use this when asked to create batch jobs, scheduled tasks, chunk-oriented processing, or task-oriented jobs. |
sfcc-localization | read | Guide for localizing templates, forms, and content in Salesforce B2C Commerce. Use this when implementing multi-language support, resource bundles, locale-specific content, and internationalization features. |
sfcc-localserviceregistry | read | Guide for creating server-to-server integrations in Salesforce B2C Commerce using LocalServiceRegistry. Use this when asked to integrate external APIs, create HTTP services, implement OAuth flows, or configure service credentials. |
sfcc-logging | read | Guide for implementing logging in Salesforce B2C Commerce scripts |
sfcc-ocapi-hooks | read | Guide for implementing OCAPI hooks in Salesforce B2C Commerce. Use this when asked to create OCAPI hooks, extend API endpoints, validate API requests, or modify API responses. |
sfcc-ocapi-scapi-slas | read | Decision guide for OCAPI vs SCAPI, and practical SLAS token lifecycle guidance (guest tokens, refresh rotation, public vs private clients, and hybrid SFRA/headless auth). Use this when planning integrations or debugging auth/rate-limit issues. |
sfcc-page-designer | read | Guide for creating Page Designer pages and components in Salesforce B2C Commerce |
sfcc-performance | read | Performance optimization strategies for Salesforce B2C Commerce Cloud including caching, efficient data retrieval, index-friendly APIs, and job optimization. Use when asked about SFCC performance, caching strategies, or optimization. |
sfcc-platform-limits | read | Cheat-sheet and design patterns for surviving SFCC quotas and limits (script timeouts, HTTPClient call caps, session size, custom object quotas, file I/O restrictions, and headless rate limits). Use this when debugging enforced quota violations or designing scalable SFCC architectures. |
sfcc-scapi-custom-endpoints | read | Guide for developing SCAPI Custom APIs on Salesforce B2C Commerce. Use this when asked to create custom REST endpoints, api.json, schema.yaml, or script implementations. |
sfcc-scapi-hooks | read | Guide for implementing SCAPI hooks in Salesforce B2C Commerce. Use this when asked to create SCAPI hooks, extend Shopper API endpoints, validate API requests, or modify API responses for headless commerce. |
sfcc-script-evaluation | write | Guide for using the evaluate_script tool to execute JavaScript on SFCC instances via the script debugger |
sfcc-security | read | Secure coding best practices for Salesforce B2C Commerce Cloud including CSRF protection, authentication, authorization, cryptography, and secrets management. Use when asked about SFCC security, input validation, or secure coding patterns. |
sfcc-sfra-client-side-js | read | Guide for extending, structuring, validating, and optimizing client-side JavaScript in SFRA storefronts. Use when asked to build AJAX flows, form validation, DOM interactions, or client-side customizations. |
sfcc-sfra-controllers | read | Guide for developing SFRA controllers in Salesforce B2C Commerce. Use this when asked to create controllers, extend base functionality, implement middleware chains, handle routing, or customize storefront behavior. |
sfcc-sfra-models | read | Guide for creating, extending, and customizing models within SFRA. Use this when asked to develop product models, cart models, customer models, or any JSON transformation layer in SFCC. |
sfcc-sfra-scss | read | Best practices for styling and theming SFRA storefronts using SCSS. Use when asked to create style overrides, theming, responsive layouts, or CSS customizations in SFCC. |
sfcc-webdav-workflows | read | Practical guide for using WebDAV in Salesforce B2C Commerce Cloud for IMPEX transfers and log access. Use this when setting up WebDAV clients, debugging WebDAV permission issues, or designing automation that reads/writes files via WebDAV. |
summarize_logs | read | Get a health overview of all log activity with counts and key issues. Use as first step when investigating problems or for daily health checks. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
- **Auth Service (AuthTokenService.js)**: Handles the POST request to the token endpoint.
.DS_Store
.DS_Store
this.logger.debug(`Requesting token from: ${authUrl}`);this.logger.error(`Failed to get access token: ${message}`);this.logger.debug(`[WorkspaceRoots] password: ${config.password ? '(set)' : '(not set)'}`);this.logger.debug(`[WorkspaceRoots] client-secret: ${config['client-secret'] ? '(set)' : '(not set)'}`);.DS_Store
.DS_Store
console.log(` Client Secret: ${this.config.validCredentials.clientSecret}`);import { CacheManager } from '../../utils/cache.js';import { Logger } from '../../utils/logger.js';} from '../../utils/markdown-utils.js';
import { buildCategoryList, CategoryInfo } from '../../utils/category-utils.js';import { Logger } from '../../utils/logger.js';vitepress
cors, express
This server is designed for local, single-developer use. It does not store credentials on disk or transmit them to third-party services.
**Description:** Searches for a single profile instance. The search can be configured using a simple query language, which provides most common filter and operator functionality. The identifier for an
**Description:** Searches for profile instances. The search can be configured with a map, which key-value pairs are converted into a query expression. The key-value pairs are turned into a sequence of
**Description:** Searches for a single profile instance. The search can be configured using a simple query language, which provides most common filter and operator functionality. The identifier for an
| Data Scope | Full access to parent `pdict` & variables | Isolated – only URL query params available |
The class provides access to the values in the pipeline dictionary. You use dynamic properties to access values, such as pdict.myvalue or pdict['myvalue']; The class is used in two different contexts,
Provides access to the constraints of customer passwords. An instance of this class can be obtained via CustomerMgr.getPasswordConstraints().
The class represents a customer profile. It also provides access to the customers address book and credentials. Note: this class handles sensitive security-related data. Pay special attention to PCI D
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
37d925b6f7d6full audit observations/trust-audit/mcp-server/taurgis__sfcc-dev.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 37d925b6f7d6 | BLOCK | D | 69 | first audit |
Questions
What is the SFCC Dev MCP server?
Supercharge your Salesforce B2C Commerce Cloud development with AI-powered documentation access, real-time log analysis, and intelligent best practices guidance
What tools does SFCC Dev expose?
62 in total: 59 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SFCC Dev safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does SFCC Dev need?
It reads SFCC_CLIENT_SECRET and SFCC_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SFCC Dev run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as sfcc-mock-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (37d925b6f7d6), read on 2026-10-08. The repository is watched and re-audited when it changes.