跳到主内容
智客 ZICQ

技能库 智客分类:Agent 工作流 platform-models-api-configure

平台模型 Api 配置

配置(或出错)一个AI编码代理或CLI,通过销售力模型 API 使用已签名的 OrgJWT 进行路由. 在将代理指向销售力模型端点(api.salesforce.com/ai/gpt/v1)时使用此技能,设置了OrgJWT / Bedrock-mode auuth,线接代理设置,API-键帮助器,以及销售力模型端点的证书文件,或者固定模型 API 401 / 404 /\"模型不可用"出错. 当用户需要创建或配置 Salesforce Connected App 本身(使用集成-连接-连接-应用-配置)或设置取名证书 / callout auth(使用集成-连接-生成)时,请不要TRIGGER.

4088 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

配置(或出错)一个AI编码代理或CLI,通过销售力模型 API 使用已签名的 OrgJWT 进行路由. 在将代理指向销售力模型端点(api.salesforce.com/ai/gpt/v1)时使用此技能,设置了OrgJWT / Bedrock-mode auuth,线接代理设置,API-键帮助器,以及销售力模型端点的证书文件,或者固定模型 API 401 / 404 /\"模型不可用"出错. 当用户需要创建或配置 Salesforce Connected App 本身(使用集成-连接-连接-应用-配置)或设置取名证书 / callout auth(使用集成-连接-生成)时,请不要TRIGGER.

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Salesforce Models API setup for an AI coding agent、Prerequisite、Inputs to collect、Steps (reference implementation)、Capturing as a runbook (when asked to document, not apply)、Verify before finishing。 其中含规范建议的小节:分步指令。

文件分析

文件分析:除 SKILL.md 外,正文引用了 scripts/get-orgjwt.sh,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / \"model not available\" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use integration-connectivity-connected-app-configure) or set up Named Credentials / callout auth (use integration-connectivity-generate).

Salesforce Models API setup for an AI coding agentPrerequisiteInputs to collectSteps (reference implementation)Capturing as a runbook (when asked to document, not apply)Verify before finishingMust be exact (each prevents a specific failure)Diagnose

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
platform-models-api-configure
description
Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / \"model not available\" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use integration-connectivity-connected-app-configure) or set up Named Credentials / callout auth (use integration-connectivity-generate).
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 1
  • scripts/get-orgjwt.sh

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「platform-models-api-configure」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-7e7be86b2f5a8ff4-%E5%B9%B3%E5%8F%B0%E6%A8%A1%E5%9E%8B-Api-%E9%85%8D%E7%BD%AE.html
请存为 .cursor/skills/platform-models-api-configure/SKILL.md 或 .claude/skills/platform-models-api-configure/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/forcedotcom/sf-skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/forcedotcom/sf-skills' --list

npx skills add 'https://github.com/forcedotcom/sf-skills' --skill 'platform-models-api-configure'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: platform-models-api-configure description: "Configure (or troubleshoot) an AI coding agent or CLI to route through the Salesforce Models API using a signed OrgJWT. Use this skill when pointing an agent at the Salesforce model endpoint (api.salesforce.com/ai/gpt/v1), setting up OrgJWT / Bedrock-mode auth, wiring the agent's settings, API-key helper, and credentials file for the Salesforce endpoint, or fixing Models API 401 / 404 / \"model not available\" errors. DO NOT TRIGGER when the user needs to create or configure the Salesforce Connected App itself (use integration-connectivity-connected-app-configure) or set up Named Credentials / callout auth (use integration-connectivity-generate)." metadata: cliTools: - tool: ["curl"] semver: ">=7.29.0" - tool: ["jq"] semver: ">=1.6.0" - tool: ["sf"] semver: ">=2.0.0" relatedSkills: - "integration-connectivity-connected-app-configure" - "integration-connectivity-generate" version: "1.0" domains: ["Platform", "Agentforce"] --- # Salesforce Models API setup for an AI coding agent The Salesforce Models API (`https://api.salesforce.com/ai/gpt/v1`) is authenticated with a signed **OrgJWT** (obtained via `client_credentials` with the `sfap_api` scope — see `scripts/get-orgjwt.sh`; no proxy). That auth and the base URL are the same for **any** agent. How each agent then talks to the endpoint is agent-specific: Anthropic clients (**Claude Code** and the **Claude Agent SDK**) route through **Bedrock mode** (the env vars in Step 3), whereas other agents (e.g. Codex) use their own client config against the same endpoint and token — Bedrock mode does **not** apply to them. The steps below are the **Claude Code / Claude Agent SDK reference implementation** (Bedrock mode + a JSON settings file + an API-key helper). For a non-Bedrock agent, reuse the OrgJWT auth (Step 1) and the base URL, and apply the equivalent client settings in that agent's own config location instead of the Bedrock env vars. Bundled scripts are in `scripts/`. Path placeholders below: `` = the absolute path to **this skill's own directory** (the folder containing this `SKILL.md`; resolve it from the skill path in context). `` = the absolute path to the user's project root. Always emit fully resolved absolute paths — the API-key helper runs from an undefined working directory, so relative paths break it. ## Prerequisite A connected app in the org with the **`sfap_api`** OAuth scope and the **client_credentials** flow enabled (consumer key/secret + a run-as user). Setup steps: https://developer.salesforce.com/docs/ai/agentforce/guide/access-models-api-with-rest.html `curl` + `jq` installed. ## Inputs to collect - `SF_INSTANCE_URL` — org My Domain, e.g. `https://acme.my.salesforce.com` - `SF_CLIENT_ID`, `SF_CLIENT_SECRET` — connected-app consumer key/secret - Models API base URL: `https://api.salesforce.com/ai/gpt/v1` - Model: a fully qualified `sfdc_ai__…` name, e.g. `sfdc_ai__DefaultBedrockAnthropicClaude46Sonnet` (full list: https://developer.salesforce.com/docs/ai/agentforce/guide/supported-models.html) - Scope: project (`/.claude/settings.json`, default) or user (`~/.claude/settings.json`) — reference-agent settings paths - Headers — `` = `x-client-feature-id` (default `ai-platform-models-connected-app`), `` = `x-sfdc-app-context` (default `EinsteinGPT`). Used in the Step 2 verify curl and in `ANTHROPIC_CUSTOM_HEADERS`. ## Steps (reference implementation) Concrete values for a JSON-settings + API-key-helper agent. Reuse the OrgJWT auth, verify curl, and base URL verbatim for any agent; adapt the settings-file location and env-var wiring to the target agent. 1. Write `/.claude/.orgjwt.env` (chmod 600), gitignore it: ```ini SF_INSTANCE_URL="..." SF_CLIENT_ID="..." SF_CLIENT_SECRET="..." ``` 2. Verify — must return `200` before writing settings: ```bash TOKEN=$(bash /scripts/get-orgjwt.sh /.claude/.orgjwt.env) curl -s -o /dev/null -w '%{http_code}\n' \ /model//invoke-with-response-stream \ -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ -H 'x-client-feature-id: ' -H 'x-sfdc-app-context: ' \ --data '{"anthropic_version":"bedrock-2023-05-31","max_tokens":16,"messages":[{"role":"user","content":"hi"}]}' ``` 3. Write `.claude/settings.json` (merge into existing; keep other keys): ```json { "apiKeyHelper": "bash /scripts/get-orgjwt.sh /.claude/.orgjwt.env", "model": "", "env": { "ANTHROPIC_AUTH_TOKEN": "", "CLAUDE_CODE_USE_BEDROCK": "1", "CLAUDE_CODE_SKIP_BEDROCK_AUTH": "1", "ANTHROPIC_BEDROCK_BASE_URL": "", "ANTHROPIC_SMALL_FAST_MODEL": "", "ANTHROPIC_DEFAULT_MODEL": "", "ANTHROPIC_CUSTOM_HEADERS": "x-client-feature-id: \nx-sfdc-app-context: " } } ``` Use absolute paths in `apiKeyHelper`. (`` / `` defaults are in "Inputs to collect" above.) 4. Tell the admin to fully restart the agent (`claude` for the reference agent) — settings and the API-key helper load at startup only. ### Capturing as a runbook (when asked to document, not apply) If the user wants the setup written up for review instead of applied to their machine (e.g. "save it as a Markdown runbook"), write **all** of the above into the requested file (e.g. `models-api-setup-runbook.md`), in order and self-contained: the exact `.orgjwt.env` contents, the `chmod 600` + gitignore note, the verification curl (with the "must be `200` before writing settings" note), the full `settings.json` block with every key from Step 3, and the final "fully restart `claude`" step. Don't omit any of the nine `settings.json` keys. ## Verify before finishing - [ ] `.claude/.orgjwt.env` created, `chmod 600`, and gitignored - [ ] Verification curl returned HTTP `200` before `settings.json` was written - [ ] `ANTHROPIC_AUTH_TOKEN` set to `""` in `settings.json` - [ ] `CLAUDE_CODE_USE_BEDROCK` set to `"1"` - [ ] `CLAUDE_CODE_SKIP_BEDROCK_AUTH` set to `"1"` - [ ] `ANTHROPIC_BEDROCK_BASE_URL` is exactly `https://api.salesforce.com/ai/gpt/v1` (no trailing slash/path) - [ ] `model`, `ANTHROPIC_DEFAULT_MODEL`, and `ANTHROPIC_SMALL_FAST_MODEL` all use the fully qualified `sfdc_ai__…` alias - [ ] `ANTHROPIC_CUSTOM_HEADERS` contains `x-client-feature-id` and `x-sfdc-app-context` - [ ] `apiKeyHelper` uses absolute paths (`bash /scripts/get-orgjwt.sh /.claude/.orgjwt.env`) - [ ] User told to fully restart `claude` ## Must be exact (each prevents a specific failure) - `"ANTHROPIC_AUTH_TOKEN": ""` — clears any global token that would otherwise outrank `apiKeyHelper` (precedence: `ANTHROPIC_AUTH_TOKEN` > `ANTHROPIC_API_KEY` > `apiKeyHelper`). Without it → wrong/old bearer → 401/404. - `CLAUDE_CODE_USE_BEDROCK=1` — activates the Bedrock API client; without it Claude Code uses the standard Anthropic API protocol and ignores `ANTHROPIC_BEDROCK_BASE_URL` entirely, so every call bypasses the Models API. - `CLAUDE_CODE_SKIP_BEDROCK_AUTH=1` — else Claude Code overwrites `Authorization` with AWS SigV4 and the OrgJWT never lands. - `apiKeyHelper` must be invoked as `bash ` (avoids exit-126). - Model must be a fully qualified `sfdc_ai__…` name (see supported models). - Auth is the OrgJWT from `client_credentials` (a signed JWT, 2 dots, scope `sfap_api`) — NOT `sf org display` (unsigned session token → 404). `sf` CLI has no client_credentials command; the helper calls `/services/oauth2/token`. - Only `ANTHROPIC_BEDROCK_BASE_URL` routes; no tenant-id header needed. ## Diagnose | Error | Meaning | Check first | |-------|---------|-------------| | `401` | Token is not a valid OrgJWT | Connected App `sfap_api` scope, `client_credentials` flow enabled, consumer key/secret in `.orgjwt.env`; `ANTHROPIC_AUTH_TOKEN` not cleared to `""` | | `404` | Token valid but model/env/org not routable | Fully qualified `sfdc_ai__…` model alias, `ANTHROPIC_BEDROCK_BASE_URL` exactly `https://api.salesforce.com/ai/gpt/v1`, org entitled for the Models API, `ANTHROPIC_AUTH_TOKEN` cleared | | `model not available` | Non-alias model id | Replace with a fully qualified `sfdc_ai__…` alias (see supported models) |

相关技能

Agent 工作流

技能创建者Skill Creator

创造有效技能指南。 当用户想创造出新的技能(或更新现有的技能),以专业知识,工作流程,或工具集成来扩展克洛德的能力时,应该使用这种技能.

Agent 工作流

克劳德胡布Clawdhub

使用ClawdHub CLI搜索,安装,更新并发布从taladhub.com的代理技能. 需要获取苍蝇上的新技能时使用,将安装的技能同步到最新版本或特定版本,或者发布 npm-instainddhub CLI 的新/更新的技能文件夹.

Agent 工作流

团队指挥Agent Team Orchestration

管弦乐团多代理团队,任务设定周期,交接协议,审查工作流程. 使用时间: (1)建立2+特派员队伍,具有不同专业,(2)确定任务路线和生命周期(收录框_ spec_建设_审查_完成),(3)在特派员之间制定交接协议,(4)建立审查和质量关口,(5)管理特派员之间的交流和文物共享.

Agent 工作流

超级力量Superpowers

Spec-first,TDD,子代理驱动的软件开发工作流程. 当:(1)构建任何新功能或应用——触发脑暴_计划_子代理执行回路,(2)调试出一个bug或测试失败——触发系统性的根起过程,(3)用户说"让我们构建","帮助我计划","我想添加X",或"这个被打破",(4)完成一个功…