Colophon · how it's built
workspacemarket.place — the stack
A real, public, Salesforce-backed marketplace with a custom React front end — whose entire backend (data model, business logic, seed data) was authored agentically from Claude Code and deployed without opening the Salesforce UI. The desk-reservation marketplace is the demo surface; the stack is the point.
Architecture
The static SPA never holds a Salesforce secret; the PHP proxy authenticates as an integration user and exposes only public-safe endpoints.
Salesforce — the backend
- Org: Developer Edition with Agentforce & Data Cloud (free, non-expiring).
- Custom objects:
Desk__c,Listing__c,SurgeEvent__c,Waitlist__c,Employee__c,Reservation__c,EscrowTxn__c. - Escrow state machine (Apex
EscrowService): purchase → Held → confirm handoff (creates the buyer's reservation) → HandoffConfirmed → release (listing sold), plus a refund path and guarded transitions.EscrowServiceTest: 4/4 pass, 100% coverage. - Access: a
WorkspaceMarket_Accesspermission set grants object + field-level access to the integration user. - Auth: an External Client App using the client-credentials OAuth flow, run-as an integration user.
The proxy — integration
- PHP on DreamHost shared hosting; client-credentials OAuth → access token → REST/SOQL.
- Secret hygiene: the Connected-App
client_id/client_secretlive in a PHP file outside the webroot (chmod 600) — never in git, never in the bundle. - Endpoints:
GET /api/desks,/api/listings,/api/surge,/api/insights(Data 360);POST /api/waitlist,/api/buy(escrow),/api/agent(Einstein desk-finder). Responses areCache-Control: no-store(live data). - Stable ids: desks expose a
Code__cexternal id (e.g. D1, OFC) so the UI/floor-map ids stay decoupled from Salesforce record ids.
Front end
- React 18 + TypeScript + Vite + Tailwind, built to a static bundle served at
/uc/; the landing page at/is hand-written static HTML. - Design system: an architect's blueprint — Space Mono for the chrome, Inter for prose; ink #26303f, paper #f5f4ee, one coral accent #ff5a3c for "on the market."
- Floor plan: a top-down SVG generated by a Python script — 48 desks in three back-to-back
blocks (with walkways), two interior office shares, and a planter. Desks carry
data-deskcodes; the app recolours them per the calendar-selected date (availability is date-driven) and reveals desk details on hover. - Soft gate: Buy/List unlock behind a client-side
@universalcontainers.comcheck (no visitor is a real UC employee — fitting). The waitlist is the real, open conversion.
Domain, DNS & hosting
The infrastructure layer is operated the same way as everything else — from Claude Code, through the portfolio's registrar and DNS tooling, not clicked together in a control panel.
- OpenSRS — registration. workspacemarket.place was registered through
OpenSRS (registered 2026-06-28, one-year term), its nameservers delegated to
DreamHost, and the domain transfer-locked (clientTransferProhibited).
Driven from the domains repo's OpenSRS API client — dry-run, then
--confirm. - DreamHost — DNS + hosting. The DNS zone (the
Arecord) is managed through the DreamHost DNS API; the static SPA and the PHP proxy are shipped to DreamHost shared hosting overssh/scp; HTTPS is a Let's Encrypt certificate. - Layout:
/landing ·/uc/marketplace ·/api/*proxy.
How it was built the point
Every artifact — the Salesforce metadata and Apex, the PHP proxy, the React app, the floor-plan SVG
generator — was authored by Claude Code and deployed with the Salesforce CLI
(sf project deploy, sf apex run, sf data query) plus
scp. The Salesforce UI was opened exactly once, to click together the External Client App.
Built through the MCPs, for real. Two Salesforce MCP servers are wired into Claude Code and have
each driven real builds against the org — no Salesforce UI. The Salesforce DX MCP
(@salesforce/mcp) deployed an Apex REST escrow endpoint via deploy_metadata —
the one the Buy button now calls. The Data 360 MCP modeled the Data Cloud layer (below).
Headless 360 layers — all three live on one page. Customer 360: the custom objects + the
escrow Apex state machine (the floor map, listings, the Buy loop). Data 360: a live Data
Cloud round trip — the "Market pulse" strip queries a Calculated Insight (avg surge-adjusted price
by kind — office-share seats ~$34 vs ~$16 for a hot desk) straight off the Listing__dlm
DMO via the CDP Query API. Agentforce / Einstein: the "Find a desk" chat is answered by
in-org Einstein, grounded on the live listings, composing real natural-language replies over a
custom Apex action.
Beta & preview pre-GA
In the same spirit as the notes below: a few Salesforce capabilities here were pre-GA at build time (mid-2026). Exactly which, and where they did — and didn't — touch the live site.
- Data 360 MCP server — Developer Preview. The whole Data Cloud layer (data streams → DLOs →
DMOs → the
Avg_Surge_Adjusted_Price_By_Desk_KindCalculated Insight behind "Market pulse") was modeled through this open-source, self-hosted preview server; GA is slated for later 2026. The boundary matters: the preview tool was build-time only — the runtime read of that insight goes through the GA Data Cloud CDP Query API. - Salesforce DX MCP (
@salesforce/mcp) — ran on GA tools only. The local, CLI-credential MCP that provisioned the objects, Apex and seed data gates its tools by release state. This build used only GA-marked tools (deploy_metadata,run_soql_query,run_apex_test) and never passed--allow-non-ga-tools, so non-GA tools likecreate_scratch_orgwere excluded. (Its cloud sibling, Salesforce Hosted MCP, reached GA in April 2026.) - Multi-Framework (native React on Salesforce) — open beta, and declined because of it. The "React hosted on the org" path is sandbox/scratch-org only and can't serve a public production site while in beta — so this site is self-hosted instead. Recorded as a stretch, not shipped.
- Agentforce Agent API — built, gateway-gated. Not a pre-GA label but an edition gate: the agent is built and Active, but the external api.salesforce.com gateway isn't onboarded for this free Developer Edition, so the chat runs on in-org Einstein instead (see Honest notes).
Honest notes
- Funds are simulated. No money moves; no desk is actually sold. It's a parody with a working spine.
- The chat is in-org Einstein, not the Agentforce agent runtime. An Agentforce agent is built and active, but the Agent API only answers through Salesforce's external gateway, which isn't onboarded for this free Developer Edition. So the chat grounds Einstein directly via Apex instead — same org AI, different door.
- Single tenant: the live marketplace is Universal Containers (Salesforce's canonical fictional company).
- SpaceMeh, the corporate booking app it "integrates" with, is fictional — the "meh" is the joke.
- No analytics, no trackers, no cookies.