Results for “Security”
9 matches across blog posts, projects, case studies and series.
Blog posts
Day 11/15 — Security Architecture: OAuth, Permissions & Least Privilege
A threat model for AI clients on Salesforce, the layers that contain them, where tokens go, why there is no integration user, and a least-privilege permission …
Feb 21, 2026Demystifying CORS, HTTP, and Security: A Builder’s Guide
That red CORS error in your console isn't a bug—it's a feature. We dive deep into HTTP protocols, the browser's Same-Origin Policy, and how to secure your auto…
Feb 21, 2026Secure Frontend Auth: The Definitive Guide to JWTs, Cookies, and Storage Strategies
Stop storing JWTs in LocalStorage. This guide breaks down the security trade-offs between storage strategies and walks through implementing a production-grade …
Oct 9, 2026Day 15/15 — Build a Complete Headless Salesforce AI Assistant
The capstone: a Next.js assistant that signs in with PKCE, lets Claude call Salesforce hosted MCP servers as the user, and asks before every write.
Oct 9, 2026Day 14/15 — Production Architecture: Governance, Monitoring & Error Handling
Take a Salesforce AI assistant to production: who approves tools, what Salesforce logs, how to classify and retry errors, and which limits and costs to plan fo…
Oct 9, 2026Day 13/15 — Headless 360 + Agentic AI Architecture
One assistant, a planner with tools, or several agents? Where Agentforce fits, what the beta Headless 360 MCP Server changes, and native React versus Next.js.
Oct 9, 2026Day 12/15 — Custom MCP Tools + Apex/Flow Business Logic
Publish your own Apex and Flow logic as tools on a custom Salesforce hosted MCP server, so the model calls your business rules instead of inventing them.
Oct 9, 2026Day 10/15 — Build Your First AI + Salesforce Workflow
Turn a chat into a workflow: a read-only meeting prep brief built with Next.js, the Claude API's MCP connector and Salesforce hosted MCP servers.