Skip to content

Snyk MCP connector

The Snyk connector brings Snyk organizations, members, licenses, assets, custom base images and Snyk Apps installs to Claude, ChatGPT, Cursor and any MCP client, so each person can ask about them and act on them inside their own Snyk access.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Snyk to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Snyk once

  1. Open Connections, choose Add connection, and pick Snyk.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste a Snyk API key. One person generates a token in Snyk and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

snyk
Snyk
Apache Airflow
Apify
Boomi
Browserbase
Caspio
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Snyk MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Snyk MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Snyk MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Snyk to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Snyk through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security

    Find every asset before a review

    Search Snyk assets by repository, image or group, filter them down to what the review covers, and get the list in one pass instead of clicking through each organization.

  • Platform

    Keep custom base images current

    List the custom base images registered in Snyk, add a new one when the platform team publishes it, and retire the ones nobody builds on any more.

  • Engineering

    See who belongs to each organization

    Pull the member list for a Snyk organization and check who has access before a new project starts or a contractor rolls off.

  • IT

    Change a member's role after a move

    When someone moves teams, update their Snyk membership from the same place the rest of the change is being handled.

  • Compliance

    Pull the license list for an audit

    Get the licenses Snyk has found across the organization's dependencies, ready to hand to legal or paste into the audit record.

  • Security

    Tidy up Snyk Apps installs

    List every Snyk App installed in the organization, check which ones are still used, and remove the ones that should not be there.

Try asking

  • “List all Snyk organizations and their members.”
  • “Which Snyk licenses appear across our organizations?”
  • “Show every Snyk app install created this month.”

See all 269 Snyk tools below

Compare

Elaichi vs Zapier MCP vs Composio for Snyk

All three can connect Snyk to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Snyk, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Snyk tools Allow or restrict single Snyk tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Snyk call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

AI tools

Snyk tools for your AI agents

269 tools are ready to call through Elaichi's MCP endpoint the moment you connect Snyk, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Snyk gets you

6 screens from the product, each doing one job for your Snyk account.

The agent

Ask about Snyk projects in plain language.

Type a question and get answers from live Snyk organizations, members and licenses.

  • organizations
  • members
  • licenses
  • app installs

Ask Elaichi to work across your apps.

List all Snyk organizations and their members.

Which Snyk licenses appear across our organizations?

Show every Snyk app install created this month.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Snyk here.

One org MCP endpoint over OAuth, no SDK and no shared Snyk API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Tool catalog

269 Snyk tools are cataloged and ready.

Browse Snyk resources and methods by name, with no custom code to write.

  • List all Snyk me
  • List all Snyk organization
  • List all Snyk members
  • Update a Snyk member by ID
ElaichiTools
Tool Action Description
List all Snyk me List Get details about the authenticated Snyk user making the request. Returns: id, username, email, orgs, code, message, error.
List all Snyk organization List List all Snyk organizations the authenticated user belongs to. Returns: name, id, slug, url, group, created.
List all Snyk members List List members of a Snyk organization. Returns each member's id, name, username, email, and role. Required: org_id.
Update a Snyk member by ID Update Update a member's role in a Snyk organization. Returns an empty 200 response on success. Required: org_id, id.
List all Snyk licenses List List all licenses for a Snyk organization, with optional filters for languages, projects, dependencies, licenses, and severity submitted in the request body. Returns: id, severity, instructions, dependencies, projects. Required: org_id.

Toolboxes

Every team gets its own Snyk toolbox.

Security, platform and engineering each see a toolbox scoped to their Snyk work.

  • Security
  • Platform Engineering
  • Application Development
  • Compliance
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

Snyk · issues and licenses

Snyk starter 18 Mar 4, 2026

Platform Engineering toolbox

Snyk · organizations and members

— 9 Mar 2, 2026

Application Development toolbox

Snyk · projects and targets

— 24 Feb 27, 2026

Compliance toolbox

Snyk · licenses and assets

Snyk starter 6 Feb 19, 2026

DevOps toolbox

Snyk · app installs and integrations

— 31 Jan 30, 2026

Engineering Leadership toolbox

Snyk · org-wide reporting

— 12 Jan 22, 2026

Shared connections

Teammates use Snyk accounts without credentials.

See who connected each Snyk account and how many teams and members share it.

  • Security EMEA
  • Platform Core
  • App Dev
  • Compliance
ElaichiConnections
Connection Scope Status Access
SN

Snyk (Security EMEA)

Connected by Emily Carter

Personal • Active 1 team · 6 members
SN

Snyk (Platform Core)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
SN

Snyk (App Dev)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
SN

Snyk (Compliance)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
SN

Snyk (DevOps)

Connected by Ryan Hayes

Personal • Active Not shared
SN

Snyk (Engineering Leadership)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Snyk call is written down.

When, who, what happened, type and resource for each Snyk request made.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

emily.carter@northwind.io

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

jake.morgan@northwind.io

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

megan.brooks@northwind.io

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

tyler.reed@northwind.io

Snyk Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

ryan.hayes@northwind.io

Snyk Organizations Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

ashley.parker@northwind.io

Snyk Organizations List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule fires and Snyk work finishes.

Fetch Snyk issues, group them, draft a digest, approve it, post back to Snyk.

Snyk digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch organizations

    Snyk

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Snyk

    Queued

Collections and dashboards

Snyk health numbers arrive on schedule.

Four metrics, 14 days of records created and a team breakdown, computed without a model.

Snyk health

Refreshed 4 minutes ago · every 15 minutes · from the organizations collection

Live

Organizations

1,284 ↓ 12%

Members

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Organizations created

Last 14 days

By team

Share of activity

Security EMEA 34%

Platform Core 27%

App Dev 21%

Compliance 18%

FAQ

Frequently asked questions

How do I connect Snyk to Claude?

Connect Snyk in Elaichi first by pasting in a Snyk API key, which you can copy from your Snyk account settings. There is no OAuth application to register and no client ID or secret to generate. Then in Claude go to Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Sign in with your Elaichi account and Snyk is available in Claude.

Does Snyk work with ChatGPT and Cursor as well as Claude?

Yes. Once Snyk is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Snyk once and every client sees it.

What can an AI agent actually do with my Snyk data?

It can list your Snyk organizations and their members, update a member's role, pull the licenses Snyk has found, search and filter assets such as repositories and container images, and manage custom base images and Snyk Apps installs. Snyk has a large set of actions, so the agent looks up the right one for each request. Short, concrete asks such as "list members of the platform organization" work better than long paragraphs.

Does connecting Snyk give the AI access to every organization?

No. Every call to Snyk runs inside the access of the person who signed in, so the AI sees only the Snyk organizations, assets and members that person can already see. Elaichi can narrow that further with restrictions, but it can never widen it beyond what Snyk itself allows.

Can my team share one Snyk connection?

Yes. One person connects Snyk in Elaichi and shares the connection with a team, and nobody else ever handles the Snyk API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the person behind every Snyk call.

Can I stop an agent from deleting or changing things in Snyk?

Yes. Restrictions in Elaichi work per action, so you can allow reading Snyk organizations, members and assets while blocking deletion of custom base images or Snyk Apps installs. A blocked action is never advertised to the AI client, so no prompt can reach it.

What happens to a Snyk connection when someone leaves?

Offboarding a person in Elaichi ends their access to Snyk through every client at once. A Snyk connection shared with a team keeps working for everyone else. If you want to remove Snyk entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client.

Does the Snyk MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Snyk is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Snyk?

Yes. Both let Claude, ChatGPT or Cursor use Snyk. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Snyk call.

How is Elaichi different from Composio for Snyk?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Snyk: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Snyk in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.