Salesforce Hosted MCP reached general availability in April 2026, while Agentforce, third-party connectors, and custom MCP servers continued to expand. Buyers now have several credible routes that overlap at “AI can work with Salesforce” but differ in user surface, tool scope, control model, and operating responsibility.
The stakes of that stall are asymmetric, because choosing wrong here does not always fail loudly. Teams can buy an agent platform to do a connector's job, or wire up a connector for what was really a customer-facing agent and operating-model project. The four options are not four brands of the same thing; they are different product categories that happen to overlap at “AI talks to Salesforce.”
This is the comparison we wish had existed when clients started asking: four real options, judged against the same six criteria, with a recommendation by scenario at the end. One disclosure before we start: GAT builds one of the four, ApexGenius. We identify that relationship so readers can separate product facts from our architecture judgment.
The six criteria that actually matter
Vendor pages answer the questions they win on. To make the options commensurable, every one below gets the same six:
- Setup time. From zero to a working connection — hours, days, or weeks?
- Capability depth. Data queries only, or metadata, code, and deployments too?
- Read/write scope. Can it change the org, and under what controls?
- Where it works. Claude? ChatGPT? Inside Salesforce itself?
- Governance. Who decides what the AI can touch, and how is it audited?
- Cost model. Included, flat subscription, per-user plus usage, or engineering time?
Option 1: Salesforce Hosted MCP servers
The native route. Salesforce hosts the MCP servers, your admin activates them in Setup, and MCP clients like Claude connect through an External Client App with standard OAuth. The pitch is control: no new vendor in the loop, access governed by the same permission sets you already manage, traffic visible to the same Event Monitoring you already run — and no separate line item, because it is included with supported editions.
The trade-off is that “Hosted MCP” is not one fixed tool bundle. Standard servers expose defined product capabilities; custom servers can curate tools backed by approved APIs, Apex actions, and Flows; broader services can have separate release status. Setup still requires admin work: External Client App configuration, server selection, permission assignment, client setup, and testing. Compare the exact server and tools you can enable—not an old generic description of the category.
Option 2: Agentforce (and Einstein with BYOLLM)
Agentforce answers a different question. The other three options connect an external assistant to Salesforce; Agentforce builds agents that live inside it — in the console, in Flows, in Slack, and, since this year's announcement with OpenAI, reaching sellers through Agentforce Sales inside ChatGPT. If the goal is customer-facing or employee-facing agents embedded where CRM work already happens, wrapped in the Einstein Trust Layer, this is the platform answer. BYOLLM support means you can run it on the frontier model you prefer rather than the default.
Two honest caveats. First, Agentforce is an application platform, not a connector — you do not “set it up,” you build, test, and maintain agents on it, which is a real project with real timelines. Second, Salesforce offers multiple buying and usage models across its AI portfolio. Confirm the current edition, entitlement, action type, Flex Credit treatment, and order-form terms with Salesforce. Budget for a platform implementation and its operation, not only a connection.
Option 3: ApexGenius
Disclosure: this one is ours. ApexGenius is a hosted Salesforce MCP for Claude and ChatGPT running in production since its 2025 launch. We built it because client work kept demanding more depth than the native servers expose, with less ceremony than a custom build.
The product packages the base connection through Salesforce OAuth and supports compatible MCP clients including Claude and ChatGPT. Its scope includes SOQL and SOSL, record operations, schema, metadata, Apex and development workflows such as tests, logs, validation, and approved deployment. Evaluate the current product tool catalog for the exact capability needed.
The cons are structural. It is a third-party vendor between your assistant and your org. Its power rides on the connected user's permissions and the implementation of each tool, so permission and action discipline are non-negotiable. Governance spans Salesforce, ApexGenius, the AI client, and the team's own approval and operating policy. Pricing uses a flat product subscription rather than an ApexGenius fee for each action, but the honest framing is that it is a different product category than Agentforce — a capability layer for the humans and assistants you already have, not an agent platform.
Option 4: A custom MCP server
Building your own buys total control: exactly the tools you want, fused with internal systems behind one server, deployed inside whatever network boundary compliance demands. A prototype is not the cost model.
Production is the real bill: OAuth token lifecycles, secret management, rate limiting, logging, upgrades when the spec moves, and a named owner forever. Custom makes sense when you have a platform team and constraints the other three cannot meet — data residency, mandated gateways, a bespoke tool surface. Absent those, it is the most expensive way to acquire something you could have configured or bought.
Side-by-side comparison
| Criterion | Hosted MCP | Agentforce | ApexGenius | Custom server |
|---|---|---|---|---|
| Implementation shape | Salesforce admin configuration, client setup, and testing | Agent design, actions, grounding, testing, and launch | Packaged connection plus permission and rollout design | Product engineering plus ongoing operation |
| Works with | Compatible MCP clients, including documented Claude and ChatGPT paths | Salesforce and supported agent channels | Claude, ChatGPT, and compatible MCP clients | Any client you target |
| Read/write | Depends on the standard or custom server and enabled tools | Actions you build and approve | Full read/write: CRUD, SOQL, Apex | Whatever you implement |
| Deploy metadata? | Service and release-status dependent; verify the enabled tool set | No — runtime agents, not a dev tool | Yes — Apex, Flows, LWC | If you build it |
| Governance model | Salesforce-native: OAuth, permission sets, Event Monitoring | Einstein Trust Layer + platform guardrails | Inherits connected user's permissions + your policy | Whatever you enforce |
| Cost model | Included with supported editions | Salesforce licensing and usage terms; verify the current order form | Flat product subscription | Engineering time + maintenance |
How to read this: implementation shape is more useful than a generic setup-time promise. Capability depth also changes by server, release, and custom tool selection. The cost column compares different shapes, not different sizes—Salesforce entitlements and usage, a flat product subscription, and owned engineering are distinct budget conversations.
Buy the category you actually need, not the demo you happened to see first.
Our recommendation, by scenario
You are building agents into the CRM experience itself. Agentforce. If the deliverable is an agent your customers or reps meet inside Salesforce, with platform guardrails and procurement-friendly compliance, build it on the platform — and budget for the project it genuinely is.
You want governed data access with zero new vendors. Hosted MCP. If you are on a supported edition and the mandate is “let people ask the org questions safely,” activate it, assign permissions tightly, curate the smallest server toolset, and verify the current capabilities against the job.
You want a packaged Salesforce operations and development connector in Claude and ChatGPT. ApexGenius. It is ours, and it packages the record, metadata, testing, and approved deployment workflows described above. Review the product scope, security model, and current pricing directly.
You are regulated, bespoke, and staffed for it. Custom. If residency, gateways, or a fused internal tool surface are hard requirements and you have a platform team to own it, build — and scope the maintenance tail honestly before you start.
These are not mutually exclusive. An organization can use Agentforce for native agents and an MCP connection for people working from other AI clients, with different controls and owners for each. For the deeper playbooks, see Claude + Salesforce and ChatGPT + Salesforce, or go straight to ApexGenius.