Skip to content

Orca Security MCP connector

The Orca Security connector brings your cloud alerts, assets, vulnerabilities, cloud accounts and scans to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person can ask about and act on Orca Security findings inside their own access.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Orca Security to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Orca Security once

  1. Open Connections, choose Add connection, and pick Orca Security.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste an Orca Security API key. One person generates a token in Orca Security and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

orca security
Orca Security
Censys
Herd Security
Infisical
Intruder
Kisi
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Orca Security MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Orca Security MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Orca Security MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Orca Security to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Orca Security through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security operations

    Triage this morning's alerts

    Ask for the open Orca Security alerts on production accounts, sorted by severity, and get the event log and recommended remediation for the ones that matter.

  • Cloud engineering

    Find what a vulnerability actually touches

    Ask which assets carry a given CVE and which cloud accounts they sit in, then read the remediation steps before opening a change.

  • Incident response

    Pull the full story behind one alert

    Get a single Orca Security alert with its event history, malware findings and linked Jira ticket in one place while the call is still going.

  • Compliance

    Check coverage across cloud accounts

    List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.

  • Platform engineering

    Kick off a scan after a deploy

    Start an Orca Security scan on a new environment or a vendor's asset and check the result later without leaving the tool you are working in.

  • Security leadership

    Summarize risk for the weekly review

    Ask for a plain-language rundown of alert counts by severity and account, with the assets driving the most findings, ready to paste into a report.

Try asking

  • “Show high severity Orca Security alerts opened this week.”
  • “Which cloud accounts have the most open vulnerabilities?”
  • “List remediation actions for critical alerts on production assets.”

See all 40 Orca Security tools below

Compare

Elaichi vs Zapier MCP vs Composio for Orca Security

All three can connect Orca Security to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Orca Security, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Orca Security tools Allow or restrict single Orca Security tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Orca Security call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

AI tools

Orca Security tools for your AI agents

40 tools are ready to call through Elaichi's MCP endpoint the moment you connect Orca Security, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Orca Security gets you

6 screens from the product, each doing one job for your Orca Security account.

The agent

Ask about Orca Security alerts in plain language.

The agent answers from live alerts, assets and cloud accounts, no query syntax.

  • alerts
  • assets
  • cloud accounts
  • vulnerabilities

Ask Elaichi to work across your apps.

Show high severity Orca Security alerts opened this week.

Which cloud accounts have the most open vulnerabilities?

List remediation actions for critical alerts on production assets.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Orca Security.

One org MCP endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Tool catalog

40 Orca Security tools, ready on connect.

Alerts, vulnerabilities, remediation actions, assets and cloud accounts, with no custom code.

  • List all Orca Security alerts
  • Get single Orca Security alert by ID
  • Orca Security alerts event logs
  • Orca Security alerts state
ElaichiTools
Tool Action Description
List all Orca Security alerts List Retrieve alerts from Orca Security. The response provides detailed information about the retrieved alerts, including their attributes and related data.
Get single Orca Security alert by ID Get Retrieves details of a specific alert identified by its id from Orca Security. The response contains information related to the alert, including remediation details, compliance status, asset details, and more.
Orca Security alerts event logs Action Use this endpoint to retrieve the event log for a specific alert by providing the alert_id. The response includes a list of events related to that alert, along with metadata for each event.
Orca Security alerts state Action Use this endpoint to retrieve the current state of a specific alert identified by its alert_id. The response includes detailed information such as the alert's severity, rule source, timestamps for creation and last update, verification status, risk level, Orca score, current status, and more.
List all Orca Security alerts scheme List Retrieves a list of alerts and their details from Orca Security. The response includes an array of "alerts" with attributes such as type, rule information, compliance status, asset details, severity, cloud provider information, connectivity details, vulnerabilities, etc.

Toolboxes

Each team gets its own Orca Security toolbox.

Curate one toolbox per team so people see the tools their work needs.

  • Security operations
  • Cloud platform
  • Vulnerability management
  • Compliance
ElaichiToolboxes
Name Source template Tools Created

Security operations toolbox

Orca Security · alerts and triage

Orca Security starter 18 Mar 4, 2026

Cloud platform toolbox

Orca Security · cloud accounts and assets

— 9 Mar 2, 2026

Vulnerability management toolbox

Orca Security · vulnerabilities and remediation actions

— 24 Feb 27, 2026

Compliance toolbox

Orca Security · asset coverage and evidence

Orca Security starter 6 Feb 19, 2026

Incident response toolbox

Orca Security · alert event logs and states

— 31 Jan 30, 2026

Engineering leads toolbox

Orca Security · open findings by service

— 12 Jan 22, 2026

Shared connections

Share an Orca Security account, never the key.

See who connected each account and how many teams and members use it.

  • Security operations
  • Cloud platform
  • Compliance
  • Incident response
ElaichiConnections
Connection Scope Status Access
OR

Orca Security (Security operations)

Connected by Emily Carter

Personal • Active 1 team · 6 members
OR

Orca Security (Cloud platform)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
OR

Orca Security (Compliance)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
OR

Orca Security (Incident response)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
OR

Orca Security (Production accounts)

Connected by Ryan Hayes

Personal • Active Not shared
OR

Orca Security (Sandbox accounts)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Orca Security call is on the record.

When, who, what happened, type and resource, in an append only log.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

emily.carter@northwind.io

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

jake.morgan@northwind.io

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

megan.brooks@northwind.io

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

tyler.reed@northwind.io

Orca Security Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

ryan.hayes@northwind.io

Orca Security Alerts Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

ashley.parker@northwind.io

Orca Security Alerts List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule turns Orca Security alerts into action.

Fetch alerts, group them, draft a digest, get approval, post back to Orca Security.

Orca Security digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch alerts

    Orca Security

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Orca Security

    Queued

Collections and dashboards

Orca Security health, counted on a schedule.

Four metrics, 14 days of alerts created, and a breakdown by team.

Orca Security health

Refreshed 4 minutes ago · every 15 minutes · from the alerts collection

Live

Alerts

1,284 ↓ 12%

Assets

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Alerts created

Last 14 days

By team

Share of activity

Security operations 34%

Cloud platform 27%

Compliance 21%

Incident response 18%

FAQ

Frequently asked questions

How do I connect Orca Security to Claude?

Two steps. In Elaichi, choose Orca Security and paste in your Orca Security API key, which is the only sign-in step, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and Orca Security is ready to use.

Does Orca Security work with ChatGPT and Cursor as well as Claude?

Yes. Once Orca Security is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Orca Security once and every client picks it up.

What can an AI agent actually do with my Orca Security data?

An agent can list and read Orca Security alerts, pull an alert's event log, vulnerabilities, malware findings, remediation actions and linked Jira ticket, browse your assets and cloud accounts, and start or check a scan. It cannot do anything the connector does not cover, and it cannot do anything the signed-in person could not do in Orca Security. Because Orca Security has many actions, short concrete asks such as "critical alerts on the payments account" get better results than long paragraphs.

Does connecting Orca Security give the AI every cloud account and alert?

No. Access follows the person who signed in, so the agent sees the Orca Security cloud accounts, assets and alerts that person's own Orca Security account can see, and nothing beyond it. Elaichi can narrow that further, for example to read-only or to a subset of actions, but it can never widen access past what Orca Security already grants.

Can my team share one Orca Security connection?

Yes. One person connects Orca Security in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so every Orca Security call in the audit log names the person who made it, not the person who connected it.

Can I stop an agent from changing or deleting things in Orca Security?

Yes. Restrictions in Elaichi work per action, so you can allow reading Orca Security alerts and assets while blocking starting scans or changing alert state. A blocked action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.

What happens to an Orca Security connection when someone leaves?

Offboarding a person in Elaichi ends their access to Orca Security through every client at once, with no need to touch Orca Security itself. If they were using a shared Orca Security connection, it keeps working for everyone else on the team. Disconnecting Orca Security once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

Does the Orca Security MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Orca Security is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Orca Security?

Yes. Both let Claude, ChatGPT or Cursor use Orca Security. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Orca Security call.

How is Elaichi different from Composio for Orca Security?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Orca Security: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Orca Security in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.