Skip to content

Drata MCP connector

The Drata connector brings your controls, assets, audits, audit requests, personnel and background checks into Claude, ChatGPT, Cursor and any MCP client, so your team can ask about compliance status and keep Drata records current inside the access each person already has.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Drata to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Drata once

  1. Open Connections, choose Add connection, and pick Drata.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste a Drata API key. One person generates a token in Drata and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

drata
Drata
Alloy
Cakewalk
Comp AI
ComplyCube
LawVu
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Drata MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Drata MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Drata MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Drata to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Drata through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Compliance

    Answer auditor requests without the scramble

    Pull up every open audit request for the SOC 2 audit, see which ones are still waiting on evidence, and get a plain summary of what the auditor still needs before the Friday check-in.

  • Security

    Keep the asset inventory honest

    After a laptop refresh, add the new devices to Drata, retire the ones that went back to the vendor, and fix the owner on anything that changed hands, all from one conversation.

  • IT

    Check who is in Drata and who is not

    Compare the Drata personnel list against the new hires and leavers from last month so nobody is missing from onboarding checks or lingering after they left.

  • People

    Kick off background checks on day one

    When a new hire is added, start their background check in Drata straight away instead of waiting for someone to remember the compliance step.

  • Engineering

    Give every control a named owner

    List the controls that have no owner in Drata, then assign them to the right engineering lead so nothing sits unowned going into the next audit window.

  • Compliance

    Write up control reviews as you go

    After a quarterly access review, add a control note in Drata recording what was checked and what was found, and tidy up notes from earlier reviews that are out of date.

Try asking

  • “List open audit requests for our SOC 2 audit.”
  • “Which Drata assets have no owner assigned?”
  • “Show users missing a completed background check.”

See all 165 Drata tools below

Compare

Elaichi vs Zapier MCP vs Composio for Drata

All three can connect Drata to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Drata, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Drata tools Allow or restrict single Drata tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Drata call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

AI tools

Drata tools for your AI agents

165 tools are ready to call through Elaichi's MCP endpoint the moment you connect Drata, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Drata gets you

6 screens from the product, each doing one job for your Drata account.

The agent

Ask about audits, get real answers.

Type a question in plain language and read it off live Drata records.

  • users
  • assets
  • audits
  • audit requests

Ask Elaichi to work across your apps.

List open audit requests for our SOC 2 audit.

Which Drata assets have no owner assigned?

Show users missing a completed background check.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor share one endpoint.

Connect any MCP client to Drata over OAuth, no SDK, no shared key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Tool catalog

165 Drata tools ready to call.

Users, assets, audits and audit requests are covered without custom code.

  • List all Drata users
  • Get single Drata user by ID
  • List all Drata assets
  • Create a Drata asset
ElaichiTools
Tool Action Description
List all Drata users List List drata users matching optional filters. Returns: id, email, firstName, lastName, jobTitle, roles, avatarUrl, drataTermsAgreedAt, createdAt, backgroundChecks, documents, and identities per user record.
Get single Drata user by ID Get Get the full detail of a single drata user by id. Returns: id, email, firstName, lastName, jobTitle, roles, avatarUrl, drataTermsAgreedAt, createdAt, backgroundChecks, documents, and identities. Required: id.
List all Drata assets List List Drata assets by search terms and filters. Returns: id, name, assetType, assetProvider, owner, device, createdAt, updatedAt, externalId, customFields.
Create a Drata asset Create Manually add a new asset to the Drata account. Returns: id, name, description, assetType, assetProvider, owner, createdAt, customFields. Required: name, description, assetClassTypes, assetType, ownerId.
Get single Drata asset by ID Get Get a single Drata asset by id. Returns: id, name, description, assetType, assetProvider, owner, device, createdAt, updatedAt, externalId, customFields. Required: id.

Toolboxes

Every team gets its own toolbox.

Curate Drata tools per team so each group sees only its work.

  • Compliance
  • Security
  • People Ops
  • IT
ElaichiToolboxes
Name Source template Tools Created

Compliance toolbox

Drata · audits and audit requests

Drata starter 18 Mar 4, 2026

Security toolbox

Drata · assets and controls

— 9 Mar 2, 2026

People Ops toolbox

Drata · users and background checks

— 24 Feb 27, 2026

IT toolbox

Drata · asset inventory and owners

Drata starter 6 Feb 19, 2026

Legal toolbox

Drata · company records and policies

— 31 Jan 30, 2026

Engineering toolbox

Drata · workspaces and evidence

— 12 Jan 22, 2026

Shared connections

Teammates work without touching a credential.

See who connected each Drata account and which teams and members share it.

  • Compliance
  • Security
  • People Ops
  • IT Operations
ElaichiConnections
Connection Scope Status Access
DR

Drata (Compliance)

Connected by Emily Carter

Personal • Active 1 team · 6 members
DR

Drata (Security)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
DR

Drata (People Ops)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
DR

Drata (IT Operations)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
DR

Drata (Legal)

Connected by Ryan Hayes

Personal • Active Not shared
DR

Drata (Audit Readiness)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Drata call has a name on it.

When, who, what happened, type and resource, appended and never edited.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

emily.carter@northwind.io

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

jake.morgan@northwind.io

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

megan.brooks@northwind.io

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

tyler.reed@northwind.io

Drata Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

ryan.hayes@northwind.io

Drata Users Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

ashley.parker@northwind.io

Drata Users List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule turns into a finished digest.

Fetch Drata audit requests, group them, draft a digest, approve, post it back.

Drata digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch users

    Drata

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Drata

    Queued

Collections and dashboards

Drata compliance numbers, counted not guessed.

Four metrics, 14 days of records created and a team breakdown, refreshed on schedule.

Drata health

Refreshed 4 minutes ago · every 15 minutes · from the users collection

Live

Users

1,284 ↓ 12%

Assets

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Users created

Last 14 days

By team

Share of activity

Compliance 34%

Security 27%

People Ops 21%

IT Operations 18%

FAQ

Frequently asked questions

How do I connect Drata to Claude?

Connect Drata in Elaichi first, which asks for a Drata API key from your Drata settings and nothing else. There is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude will ask you to sign in to Elaichi, and from then on Drata is available in your conversations.

Does Drata work with ChatGPT and Cursor as well as Claude?

Yes. Once Drata is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Drata once and every client you use picks it up.

What can an AI agent actually do with my Drata data?

With Drata connected, an agent can look up controls, assets, audits, audit requests, personnel, workspaces and control notes, and tell you in plain language where things stand. It can also add or update assets, write control notes, assign control owners, start a background check and import controls into your control library. Because Drata offers so many actions, short concrete asks work best, such as "list open audit requests for the SOC 2 audit" rather than a long paragraph.

Does connecting Drata give the AI access to my whole compliance program?

No. Every request runs as the person who signed in, so an agent working through Drata can only see and change what that person's Drata access already allows. Elaichi can narrow that further, for example limiting a team to reading controls and audits, but it can never grant anything the person does not already have in Drata.

Can my team share one Drata connection?

Yes. One person connects Drata in Elaichi and shares the connection with a team, and nobody else ever handles the Drata API key. Each teammate still signs in to Elaichi as themselves, so the audit log records exactly who asked for what in Drata.

Can I stop an agent from deleting or changing things in Drata?

Yes. In Elaichi you restrict Drata action by action, so you can allow reading controls and audits while blocking deleting assets or removing control notes. A blocked action is never shown to Claude, ChatGPT, Cursor or any other client at all, so no prompt, however worded, can reach it.

What happens to a Drata connection when someone leaves?

When you offboard someone in Elaichi, their access to Drata through every client ends immediately. If they connected Drata and shared it, the shared connection keeps working for everyone else on the team. If you want Drata gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

Does the Drata MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Drata is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Drata?

Yes. Both let Claude, ChatGPT or Cursor use Drata. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Drata call.

How is Elaichi different from Composio for Drata?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Drata: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Drata in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.