Connectors / SSO
SSO MCP connectors for Claude, ChatGPT and Cursor
10+ SSO connectors in the catalog, each behind the same governed MCP endpoint as everything else in Elaichi.
https://api.elaichi.ai/mcp
The same for every user.
-
Their own access. An agent never gets more than the person it acts for.
-
One connection, every client. Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent.
The connectors
SSO connectors in the catalog
Connect one and your whole team reaches it, each inside the access they already have, without anyone handling a credential.
10 connectors
-
Auth0 App credentials 466 tools
-
Google Hosted sign-in 121 tools
-
Google Workspace
Hosted sign-in
21
tools
-
JumpCloud API key 2 tools
-
Microsoft 365 Hosted sign-in 86 tools
-
Okta Bring your own OAuth app 318 tools
-
Stytch Hosted sign-in
-
Torii API key 27 tools
-
WorkOS Hosted sign-in
-
World API key 31 tools
No SSO connector by that name
It may sit under another category, or not be in the catalog yet — any documented API can become a connector.
In practice
What teams do with SSO connectors
Drawn from the connector pages in this category, so every line describes something one of these connectors actually does.
IT
-
Set up a new hire in Auth0
Create the user, attach the right role, and add them to their organization in one request instead of clicking through three screens.
-
Set up a new hire on day one
Create the Okta user, add them to the right groups, and confirm which applications they can now reach, all from one request.
-
Keep the user directory tidy
Look up a person by name, confirm their account details, and remove accounts that should no longer exist in Microsoft 365.
Security
-
Review what changed in Torii and who did it
Read the Torii audit log to see which users, applications, and contracts were edited, and check role assignments when an access review comes around.
-
Review admin roles and third-party tokens
List every role and who holds it, flag super admin assignments that should not exist, and see which outside apps have tokens granted by your users.
-
Review who still has an active account
Pull the full list of JumpCloud system users before an access review and spot accounts that should have been closed.
Support
-
Find the right help doc without digging
Ask for the Google Doc that covers a refund or setup question and get the current version from Drive, instead of scrolling through shared folders.
-
Find out why a verification failed
When a user says they could not prove they are human, pull up their verification and the precheck result to see what went wrong before you reply.
-
Confirm what a customer's sign-in email says
Pull up the exact Stytch email template a customer received so you can answer their question with the real text in front of you.
Operations
-
Read survey results without opening the spreadsheet
Ask what people said in a Google Form, such as an office move survey or a vendor intake, and get the responses grouped and summarized.
-
Set up channels for a new project
Create the project channels, name them to match your convention, and start the kickoff chat with the right people, all in one request.
-
Help someone recover their account
Start, execute or cancel a recovery for a user who lost their device, and add or remove authenticators once they are back in.
Once it is connected
Things to ask
Each of these is answered against the access the person asking already has, in the SSO account you connected.
-
List Auth0 users who gained the admin role this week.
-
Summarize the responses to last week's onboarding form.
-
List all Google Workspace groups with no members.
-
List every JumpCloud system user in the Finance department
-
Post a recap of today's customer call to the Northwind channel
-
Which Okta users were deactivated in the last week?
-
Show me the email templates in our production Stytch project
-
List Torii applications with no active users this quarter.
The tools
What an agent can call in SSO
- Connectors
- 10+
- Tools
- 1,072
- Hosted sign-in
- 5
in the SSO catalog
callable the moment you connect
connect with nothing to register
Of those 1,072 tools, 10% delete something. Restricting an agent to reads is not a promise here, it is 490 tools admitted and the rest left out — and a restricted tool is never advertised to the model at all.
- Read 46%
- 490 tools · list, get, search
- Write 28%
- 299 tools · create, update, send
- Delete 10%
- 107 tools · delete, remove, archive
- Other 16%
- 176 tools · vendor-specific verbs
One endpoint
https://api.elaichi.ai/mcp
Every connector above answers here.
Every SSO connector, by depth
Tool counts are what the connector exposes today; the split is what those tools do.
Hosted sign-in takes a partnership with each vendor, and more are in progress. Until one lands, Your own app means the connector works today — you register an OAuth app once and connect. API key and App credentials mean an admin pastes them once, with nothing to register.
| Connector | Tools | Read · write · delete | Sign-in |
|---|---|---|---|
| Auth0 | 466 | App credentials | |
| Okta | 318 | Your own app | |
| 121 | Hosted | ||
| Microsoft 365 | 86 | Hosted | |
| World | 31 | API key | |
| Torii | 27 | API key | |
| Google Workspace | 21 | Hosted | |
| JumpCloud | 2 | API key | |
| Stytch | Hosted | ||
| WorkOS | Hosted |
FAQ
Frequently asked questions
How many SSO connectors does Elaichi have?
10+ SSO connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.
Can Claude, ChatGPT and Cursor all use SSO connectors?
Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor or any MCP client connects to that same address with OAuth, while the Elaichi Agent reaches the same tools inside the app. Connecting a SSO account once makes it reachable from every one of them.
Do SSO connectors work with Gemini, Codex, Claude Code or other MCP clients?
Yes. SSO connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.
Do SSO connectors need me to bring my own OAuth app?
Most do not. 5 of the SSO connectors use Elaichi's hosted sign-in, with nothing to register. 4 connect with an API key or app credentials that an admin pastes once, with no app to register. 1 asks you to bring your own OAuth app: you register it once with the vendor and connect. Hosted sign-in for those is in progress, a vendor partnership at a time, and when one lands the only thing that changes is that the registration step goes away. Each connector's page says which it is before you start.
Can I stop an agent from writing to SSO tools?
Yes. Tool restrictions apply at role and individual level, and a restricted tool is left out of the model's tool list and cannot be called. Read-only access to a SSO connector is a matter of allowing the reads and leaving the writes out.
Nearby
Teams that connect SSO usually connect these too
Put SSO connectors in front of your team
14 days on Gold, no credit card. Connect one and pick what each team can call.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.