Salesforce
A Salesforce org that answers the REST, SOAP, GraphQL, Bulk, Tooling and streaming APIs the official clients call, plus an MCP server, over one org of synthetic records.
Vendor reference: https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/ ↗. Machine-readable: compat/salesforce.json.
Surfaces
| Kind | Path | Notes |
|---|---|---|
| REST | /services/data/vXX.X | sObjects, describe, SOQL query/queryAll, SOSL search, composite, limits, reports, UI API, Tooling API, Bulk API 1.0 and 2.0, Apex REST under /services/apexrest |
| SOAP | /services/Soap | partner login, partner API calls, Metadata API, Apex API |
| GraphQL | /services/data/vXX.X/graphql | UI API GraphQL queries |
| Streaming | /cometd | CometD/Bayeux for Change Data Capture and test-run channels |
| gRPC | Pub/Sub API | Change Data Capture over the Pub/Sub API |
| OAuth | /services/oauth2/token | OAuth token issue alongside the SOAP login |
| MCP | /mcp | tools modelled on Salesforce's hosted MCP servers |
API versions: REST v21.0 through v67.0
Supported
- SOQL with relationship queries, aggregates and
nextRecordsUrlpagination; SOSL search - sObject describe and global describe for the standard objects in the org
simple_salesforceand the official SDK paths listed in the README, over HTTP and TLS- Change Data Capture over CometD and the Pub/Sub gRPC API
- Reports with fixed report definitions, and
ContentVersionfile downloads - MCP tools for querying, describing and reading records
- The daily API request allowance, reported by
/limitsand inSforce-Limit-Info
Not supported
- Triggers, flows, validation-rule automation, workflow field updates, roll-up summaries and Apex execution
- GraphQL introspection and subscriptions
- Streaming channels other than Change Data Capture and test runs (no PushTopics, generic or platform-event channels)
- Multi-currency orgs; the org is single-currency
- Many standard objects and REST resources outside the documented object list
- Most Metadata API writes and deploys
Known differences and test guidance
| Scenario | Difference from Salesforce | In your tests |
|---|---|---|
| Bulk API and async jobs | Jobs complete synchronously; there is no queued or in-progress window. | Do not assert on intermediate job states. Poll as you would against Salesforce; the first poll already reports the final state. |
| Change Data Capture replay | Channel filters are not applied and the event log keeps a fixed 1000 events. | Do not assert on filtered channels or on replay beyond the last 1000 events. |
| Apex REST endpoints | Handlers are reimplemented in the replica; no Apex runs. | Assert on documented responses, not on side effects of custom Apex code. |
| SOAP partner API | The envelope maps onto the same record store as REST; there is no WSDL negotiation or SOAP header behaviour. | Do not assert on SOAP headers such as AllOrNoneHeader or AssignmentRuleHeader. |
| Notes and recycle bin | Notes have no version history, and deleted records do not age out of the recycle bin. | Do not assert that queryAll stops returning deleted rows after 15 days. |
| Daily request allowance | Sforce-Limit-Info is an exact, monotonic counter; a real org's consecutive values can arrive out of order. Exhaustion answers 403 REQUEST_LIMIT_EXCEEDED with no Retry-After, as an org does. | Assert that your client reads Sforce-Limit-Info, not on exact counts or on consecutive values increasing. |
| File contents | Files are small valid files of the declared format, not real documents. | Assert on format and metadata, not on document text. |
| Security and sharing | Profiles, permission sets, sharing and field-level security apply to the user a credential names, but not the whole platform security model; a token that names no user runs as the administrator. | Use a credential for a named user when you test access, and do not treat the replica as proof of a full org's security posture. |
Fault injection
| Key | What the client sees |
|---|---|
throttle | 403 REQUEST_LIMIT_EXCEEDED ("TotalRequests Limit exceeded.") with an exhausted Sforce-Limit-Info header |
fail_next | The next N requests fail as throttle does, then clear |
quota_limit | 403 REQUEST_LIMIT_EXCEEDED ("ApiBatchItems Limit exceeded.") once the per-window quota is spent |
error_rate | 500 UNKNOWN_EXCEPTION with an ErrorId, for the given fraction of requests |
latency_ms | Fixed added latency on every data-plane request |
Applies to every system
- The hosted data plane is read-only: a write is refused with
403 writes_disabled. A SOQL, GraphQL or searchPOSTis a read and is answered. - Faults are injected through
POST /_admin/faultson a simulator you run yourself;POST /_admin/faults/resetclears them. - Rate limits do not happen on their own unless a page says so. Use fault injection to exercise a client's backoff.
- Distributions come from aggregated metadata sketches of data Eon backs up; no customer records; all Era data is simulated.