`agent preview` fails for published Employee Agents: `bypassUser: true` is hardcoded
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- node.js, typescript
- Domain
- cli
Research direction
Compare src/agents/productionAgent.ts at lines 355-362 with src/agents/scriptAgent.ts at lines 481-493, starting with how the script path determines bypassUser. Verify with an activated Employee Agent that sf agent preview creates a session and exchanges messages without the invalid-user error.
Written by the indexing model from the issue text.
Description
sf agent preview can never start a session with a published Employee Agent:
Error - Bad Request: Invalid user ID provided on start session:
productionAgent.ts hardcodes bypassUser: true:
Per the Agent API reference, true means "use the user associated with the agent" and is only for the client credentials flow; the default is false. Employee Agents have no agent user (BotDefinition.BotUserId is null by design), so the server resolves an empty user ID.
Same org, same agent, same JWT, varying only bypassUser:
| body | result |
|---|---|
bypassUser: true (what the CLI sends) |
400 Invalid user ID provided on start session: |
bypassUser: false |
200, session created, messages exchanged |
userId (explicit) |
400 Unrecognized field "userId" |
The Agent Script path in the same package already handles this:
The production (published agent) path is missing the equivalent.
Repro: deploy and activate any Employee Agent (reproduced with coral-cloud), then sf agent preview --api-name <agent>. The agent is listed as (Published), so discovery works — only the session start fails.
Suggested fix: derive bypassUser in productionAgent.ts instead of hardcoding it, mirroring scriptAgent.ts.
Workaround: none from the CLI (no flag or env var). Calling the Agent API directly with bypassUser: false works.
Env: @salesforce/cli 2.143.6, @salesforce/plugin-agent 1.44.4, @salesforce/agents 1.10.2, Node 24.18.0, macOS arm64, Agentforce Developer Edition (API v67.0)
- Dominant language
- No language data
- Stars
- 571
- Forks
- 80
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 3
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from forcedotcom/cli
-
investigating validated
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
forcedotcom/cli#3657 · 2 comments ·
-
area:afdx owned by another team
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
forcedotcom/cli#3645 · 2 comments ·
-
bug investigating validated
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
forcedotcom/cli#3644 · 6 comments ·
-
area:afdx bug investigating owned by another team validated
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
forcedotcom/cli#3625 · 4 comments ·
-
[BUG]: NavigationMenu SourceMember name mismatch prevents source-tracked retrieve from completingOpeninvestigating validated
Difficulty 4/5 3-5 days Newbie friendliness 52/100
forcedotcom/cli#3660 · 1 comment ·
Similar issues
-
area/testing kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
modelscope/ms-swift#10287 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Doist/todoist-cli#576 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day