Known differences

Salesforce

A Salesforce org that answers the REST, SOAP, GraphQL, Bulk, Tooling and streaming APIs the official clients call, plus an MCP server, over one org of synthetic records.

Vendor reference: https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/ ↗. Machine-readable: compat/salesforce.json.

Surfaces

KindPathNotes
REST/services/data/vXX.XsObjects, describe, SOQL query/queryAll, SOSL search, composite, limits, reports, UI API, Tooling API, Bulk API 1.0 and 2.0, Apex REST under /services/apexrest
SOAP/services/Soappartner login, partner API calls, Metadata API, Apex API
GraphQL/services/data/vXX.X/graphqlUI API GraphQL queries
Streaming/cometdCometD/Bayeux for Change Data Capture and test-run channels
gRPCPub/Sub APIChange Data Capture over the Pub/Sub API
OAuth/services/oauth2/tokenOAuth token issue alongside the SOAP login
MCP/mcptools modelled on Salesforce's hosted MCP servers

API versions: REST v21.0 through v67.0

Supported

Not supported

Known differences and test guidance

ScenarioDifference from SalesforceIn your tests
Bulk API and async jobsJobs complete synchronously; there is no queued or in-progress window.Do not assert on intermediate job states. Poll as you would against Salesforce; the first poll already reports the final state.
Change Data Capture replayChannel filters are not applied and the event log keeps a fixed 1000 events.Do not assert on filtered channels or on replay beyond the last 1000 events.
Apex REST endpointsHandlers are reimplemented in the replica; no Apex runs.Assert on documented responses, not on side effects of custom Apex code.
SOAP partner APIThe envelope maps onto the same record store as REST; there is no WSDL negotiation or SOAP header behaviour.Do not assert on SOAP headers such as AllOrNoneHeader or AssignmentRuleHeader.
Notes and recycle binNotes have no version history, and deleted records do not age out of the recycle bin.Do not assert that queryAll stops returning deleted rows after 15 days.
Daily request allowanceSforce-Limit-Info is an exact, monotonic counter; a real org's consecutive values can arrive out of order. Exhaustion answers 403 REQUEST_LIMIT_EXCEEDED with no Retry-After, as an org does.Assert that your client reads Sforce-Limit-Info, not on exact counts or on consecutive values increasing.
File contentsFiles are small valid files of the declared format, not real documents.Assert on format and metadata, not on document text.
Security and sharingProfiles, permission sets, sharing and field-level security apply to the user a credential names, but not the whole platform security model; a token that names no user runs as the administrator.Use a credential for a named user when you test access, and do not treat the replica as proof of a full org's security posture.

Fault injection

KeyWhat the client sees
throttle403 REQUEST_LIMIT_EXCEEDED ("TotalRequests Limit exceeded.") with an exhausted Sforce-Limit-Info header
fail_nextThe next N requests fail as throttle does, then clear
quota_limit403 REQUEST_LIMIT_EXCEEDED ("ApiBatchItems Limit exceeded.") once the per-window quota is spent
error_rate500 UNKNOWN_EXCEPTION with an ErrorId, for the given fraction of requests
latency_msFixed added latency on every data-plane request

Applies to every system