Skip to content

Sprinto MCP connector

Connect Sprinto to Claude, ChatGPT, Cursor and any MCP client through Elaichi, so your team can check compliance status, controls, audits, policies, vendors and risks, and create risks or onboard staff, with every call logged.

  • How it connects. Connects over OAuth. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

  • Regions. US, EU, India and AU. Elaichi supports all of them; you pick your region when you connect.

How to connect

How to connect Sprinto to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Sprinto once

  1. Open Connections, choose Add connection, and pick Sprinto.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Approve it in Sprinto. Sprinto's own window opens. Whoever approves it decides what this connection can reach.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

sprinto
Sprinto
Alloy
Cakewalk
Comp AI
ComplyCube
Drata
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Sprinto MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Sprinto MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Sprinto MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Sprinto to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Sprinto through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Compliance

    Know where the audit stands before the auditor asks

    Ask which controls are still failing and which evidence is missing for the SOC 2 or ISO 27001 audit in Sprinto, then get a plain list to work through.

  • Security

    Catch failing controls the day they fail

    Check which controls in Sprinto dropped out of compliance this week and who owns them, instead of waiting for the next review meeting.

  • People

    Onboard a new hire into compliance on day one

    Add a new US employee to Sprinto so their policy acknowledgments and training show up on their first morning, not after someone remembers.

  • Procurement

    Review a vendor before the renewal lands

    Pull up a vendor's status and risk rating in Sprinto before signing the renewal, so the security review is not an afterthought.

  • Leadership

    Log a risk the moment it surfaces

    When a meeting turns up a new risk, create it in Sprinto on the spot with the owner and severity, rather than leaving it in a notes app.

  • Legal

    Update a policy and confirm it took

    Push the revised wording of an access control policy into Sprinto and check it is marked current, all from the same conversation.

Try asking

  • “Which controls are failing ahead of our SOC 2 audit?”
  • “List vendors with a security review due this quarter.”
  • “Create a risk for the unpatched laptops finding.”

Native MCP

Why connect Sprinto's MCP server through Elaichi

Sprinto builds and runs this MCP server. Elaichi sits in front of it, so Sprinto's tools follow the same sign-in, access rules and audit log as every other connector your organization uses. Calls an AI client makes to Sprinto's server directly, outside Elaichi, get none of this.

  • One address for every AI client

    Claude, ChatGPT and Cursor reach Sprinto's tools at https://api.elaichi.ai/mcp, the same address as every other connected app. Nobody adds Sprinto's server to each client one by one.

  • Each person signs in as themselves

    Each person signs in to Elaichi as themselves. Members connect with their own Sprinto sign-in, and a connection someone shares runs on its owner's account. The credential stays in Elaichi's separate credential service, and the AI client holds only its Elaichi sign-in.

  • Rules checked before a call leaves

    Restrictions on a role or a person, for the whole connector or a single tool, are checked before a call reaches Sprinto's server. By default, a tool Sprinto does not mark read-only or non-destructive counts as destructive, and over MCP it needs the "Delete data and remove access" consent.

  • One audit log for every app

    Each call that runs is recorded with the person, the tool, the connection and the AI client that made it, in the same audit log as every other app.

  • Tool issues go to Sprinto

    Sprinto builds and runs these tools, and Elaichi staff do not curate them, so a report about how a tool behaves goes to the Sprinto team.

    support@sprinto.com

Why run a vendor's MCP server through Elaichi

Compare

Elaichi vs Zapier MCP vs Composio for Sprinto

All three can connect Sprinto to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Sprinto, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Sprinto tools Allow or restrict single Sprinto tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Sprinto call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

See it in Elaichi

What connecting Sprinto gets you

5 screens from the product, each doing one job for your Sprinto account.

The agent

Ask Sprinto about your audit in plain words.

Live answers on controls, policies, vendors and risks, no dashboard digging.

  • controls
  • policies
  • vendors
  • risks

Ask Elaichi to work across your apps.

Which controls are failing ahead of our SOC 2 audit?

List vendors with a security review due this quarter.

Create a risk for the unpatched laptops finding.

Also runs in Claude, ChatGPT or Cursor

MCP clients

One endpoint puts Sprinto in every AI client.

Claude, ChatGPT and Cursor share one governed endpoint, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Toolboxes

Each team gets its own Sprinto toolbox.

Security, People and Procurement each see only the Sprinto work that is theirs.

  • Security
  • Compliance
  • People
  • Procurement
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

Sprinto · controls and evidence

Sprinto starter 18 Mar 4, 2026

Compliance toolbox

Sprinto · audits and policies

— 9 Mar 2, 2026

People toolbox

Sprinto · staff onboarding

— 24 Feb 27, 2026

Procurement toolbox

Sprinto · vendor reviews

Sprinto starter 6 Feb 19, 2026

IT toolbox

Sprinto · devices and access

— 31 Jan 30, 2026

Leadership toolbox

Sprinto · risks and status

— 12 Jan 22, 2026

Shared connections

Teammates use Sprinto without touching a credential.

One person connects Sprinto, shares it with teams, and nobody else handles a secret.

  • Security
  • Compliance
  • People Ops
  • Procurement
ElaichiConnections
Connection Scope Status Access
SP

Sprinto (Security)

Connected by Emily Carter

Personal • Active 1 team · 6 members
SP

Sprinto (Compliance)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
SP

Sprinto (People Ops)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
SP

Sprinto (Procurement)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
SP

Sprinto (IT)

Connected by Ryan Hayes

Personal • Active Not shared
SP

Sprinto (Leadership)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Sprinto action is logged with a name.

When, who, what happened and which control or risk, in an append-only log.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

emily.carter@northwind.io

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

jake.morgan@northwind.io

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

megan.brooks@northwind.io

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

tyler.reed@northwind.io

Sprinto Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

ryan.hayes@northwind.io

Sprinto Controls Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

ashley.parker@northwind.io

Sprinto Controls List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule drafts your weekly compliance digest.

Failing controls are fetched, grouped and drafted, a person approves, then it posts to Sprinto.

Sprinto digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch controls

    Sprinto

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Sprinto

    Queued

Collections and dashboards

Sprinto health numbers refresh without being asked.

Four metrics, 14 days of risks created and a team breakdown, computed with no model.

Sprinto health

Refreshed 4 minutes ago · every 15 minutes · from the controls collection

Live

Controls

1,284 ↓ 12%

Policies

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Controls created

Last 14 days

By team

Share of activity

Security 34%

Compliance 27%

People Ops 21%

Procurement 18%

FAQ

Frequently asked questions

How do I connect Sprinto to Claude?

Connect Sprinto in Elaichi first: you sign in to Sprinto over OAuth, approve the access it asks for, and the connection is live. There is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude signs in to Elaichi and Sprinto appears in its tool list.

Does Sprinto work with ChatGPT and Cursor as well as Claude?

Yes. Once Sprinto is connected in Elaichi, Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent all use the same endpoint, https://api.elaichi.ai/mcp. You connect Sprinto once and every client picks it up.

What can an AI agent actually do with my Sprinto data?

It can check your compliance status, controls, audits, policies, vendors and risks in Sprinto and answer questions about them in plain language. It can also take actions, such as creating a risk, updating a policy or onboarding a new US staff member. Short, specific asks work best, for example which controls are failing this week, rather than a long paragraph.

Does connecting Sprinto give the AI everything in my workspace?

No. Every call to Sprinto runs as the person who signed in, so the AI sees only the controls, audits, vendors and risks that person can already see in Sprinto. Elaichi can narrow that access further with restrictions, and it can never widen it beyond what Sprinto itself allows.

Can my team share one Sprinto connection?

Yes. One person connects Sprinto in Elaichi and shares it with a team, and nobody else ever handles a credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person who checked a control or created a risk in Sprinto.

Can I stop an agent from deleting or changing things in Sprinto?

Yes. Restrictions in Elaichi work per action, so you can allow reading controls and audits in Sprinto while blocking anything that updates a policy or creates a risk. A restricted action is left out of the AI client's tool list entirely, so it cannot be called no matter what the prompt says.

What happens to a Sprinto connection when someone leaves?

Offboarding that person in Elaichi ends their access to Sprinto through every AI client at once. A connection they shared with a team keeps working for everyone else. If you want Sprinto gone entirely, disconnect it once in Elaichi and it disappears from Claude, ChatGPT, Cursor and every other client.

Does the Sprinto MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Sprinto is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Sprinto?

Yes. Both let Claude, ChatGPT or Cursor use Sprinto. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Sprinto call.

How is Elaichi different from Composio for Sprinto?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Sprinto: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Sprinto in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.