Sprinto MCP connector
Connect Sprinto to Claude, ChatGPT, Cursor and any MCP client through Elaichi, so your team can check compliance status, controls, audits, policies, vendors and risks, and create risks or onboard staff, with every call logged.
-
How it connects. Connects over OAuth. The credential goes into a vault nobody reads back.
-
One address. https://api.elaichi.ai/mcp, the same for every user.
-
Their own access. An agent never gets more than the person it acts for.
-
Regions. US, EU, India and AU. Elaichi supports all of them; you pick your region when you connect.
How to connect
How to connect Sprinto to Claude, ChatGPT or Cursor
Two steps, about a minute.
In Elaichi
Connect Sprinto once
-
Open Connections, choose Add connection, and pick Sprinto.
-
Optionally set Share with to give a team access, then press Connect.
-
Approve it in Sprinto. Sprinto's own window opens. Whoever approves it decides what this connection can reach.
The credential is vaulted. Nobody reads it back, not even the AI.
Add connection
Choose a connector.
In your AI client
Point it at one endpoint
Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.
Sprinto MCP connector for Claude
-
1
Open Customize, then Connectors.
-
2
Press Add.
-
3
Name it, paste the MCP server URL, then Continue.
https://api.elaichi.ai/mcp -
4
Sign in and approve.
On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.
Sprinto MCP connector for ChatGPT
-
1
Open Plugins, then press the + button.
-
2
Name it and paste the endpoint into Server URL.
https://api.elaichi.ai/mcp -
3
Leave Authentication on OAuth, then tick the risk acknowledgement.
-
4
Press Create, then sign in and approve.
Works on the web today. The plugin directory lives at chatgpt.com/plugins.
Sprinto MCP connector for Cursor
-
1
Open
~/.cursor/mcp.json. -
2
Add the endpoint under
mcpServers.https://api.elaichi.ai/mcp -
3
Reload Cursor, then sign in and approve.
~/.cursor/mcp.json
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
Set up per machine, so repeat it on each computer you work from.
Connect Sprinto to any MCP client
-
1
Add the endpoint as a remote MCP server.
https://api.elaichi.ai/mcp -
2
Sign in and approve.
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
The Elaichi Agent already has these tools, with nothing to set up.
Use cases
What teams do with Sprinto through Elaichi
Every one of these runs inside the access the person already has, and lands in the same audit log.
-
Compliance
Know where the audit stands before the auditor asks
Ask which controls are still failing and which evidence is missing for the SOC 2 or ISO 27001 audit in Sprinto, then get a plain list to work through.
-
Security
Catch failing controls the day they fail
Check which controls in Sprinto dropped out of compliance this week and who owns them, instead of waiting for the next review meeting.
-
People
Onboard a new hire into compliance on day one
Add a new US employee to Sprinto so their policy acknowledgments and training show up on their first morning, not after someone remembers.
-
Procurement
Review a vendor before the renewal lands
Pull up a vendor's status and risk rating in Sprinto before signing the renewal, so the security review is not an afterthought.
-
Leadership
Log a risk the moment it surfaces
When a meeting turns up a new risk, create it in Sprinto on the spot with the owner and severity, rather than leaving it in a notes app.
-
Legal
Update a policy and confirm it took
Push the revised wording of an access control policy into Sprinto and check it is marked current, all from the same conversation.
Try asking
- “Which controls are failing ahead of our SOC 2 audit?”
- “List vendors with a security review due this quarter.”
- “Create a risk for the unpatched laptops finding.”
Native MCP
Why connect Sprinto's MCP server through Elaichi
Sprinto builds and runs this MCP server. Elaichi sits in front of it, so Sprinto's tools follow the same sign-in, access rules and audit log as every other connector your organization uses. Calls an AI client makes to Sprinto's server directly, outside Elaichi, get none of this.
-
One address for every AI client
Claude, ChatGPT and Cursor reach Sprinto's tools at https://api.elaichi.ai/mcp, the same address as every other connected app. Nobody adds Sprinto's server to each client one by one.
-
Each person signs in as themselves
Each person signs in to Elaichi as themselves. Members connect with their own Sprinto sign-in, and a connection someone shares runs on its owner's account. The credential stays in Elaichi's separate credential service, and the AI client holds only its Elaichi sign-in.
-
Rules checked before a call leaves
Restrictions on a role or a person, for the whole connector or a single tool, are checked before a call reaches Sprinto's server. By default, a tool Sprinto does not mark read-only or non-destructive counts as destructive, and over MCP it needs the "Delete data and remove access" consent.
-
One audit log for every app
Each call that runs is recorded with the person, the tool, the connection and the AI client that made it, in the same audit log as every other app.
-
Tool issues go to Sprinto
Sprinto builds and runs these tools, and Elaichi staff do not curate them, so a report about how a tool behaves goes to the Sprinto team.
Compare
Elaichi vs Zapier MCP vs Composio for Sprinto
All three can connect Sprinto to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.
| What to check | Elaichi | Zapier MCP | Composio |
|---|---|---|---|
| Where the AI connects |
One address for the whole organization.
https://api.elaichi.ai/mcp
|
A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Sprinto tools | Allow or restrict single Sprinto tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Sprinto call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |
Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.
Longer take: Zapier MCP alternative and when you don't need an MCP gateway.
See it in Elaichi
What connecting Sprinto gets you
5 screens from the product, each doing one job for your Sprinto account.
The agent
Ask Sprinto about your audit in plain words.
Live answers on controls, policies, vendors and risks, no dashboard digging.
- controls
- policies
- vendors
- risks
Ask Elaichi to work across your apps.
Which controls are failing ahead of our SOC 2 audit?
List vendors with a security review due this quarter.
Create a risk for the unpatched laptops finding.
Also runs in Claude, ChatGPT or Cursor
MCP clients
One endpoint puts Sprinto in every AI client.
Claude, ChatGPT and Cursor share one governed endpoint, no SDK and no shared API key.
Copy the endpoint
Toolboxes
Each team gets its own Sprinto toolbox.
Security, People and Procurement each see only the Sprinto work that is theirs.
- Security
- Compliance
- People
- Procurement
Shared connections
Teammates use Sprinto without touching a credential.
One person connects Sprinto, shares it with teams, and nobody else handles a secret.
- Security
- Compliance
- People Ops
- Procurement
Audit log
Every Sprinto action is logged with a name.
When, who, what happened and which control or risk, in an append-only log.
- When
- Who
- What happened
- Type
Launching soon
From answering questions to doing the work
A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.
Automations
A schedule drafts your weekly compliance digest.
Failing controls are fetched, grouped and drafted, a person approves, then it posts to Sprinto.
Sprinto digest
Run 418 · started 2 minutes ago · on behalf of Emily Carter
-
✓
Schedule
Every weekday at 8:00 AM
0.2s -
✓
Fetch controls
Sprinto
1.4s -
✓
Group by owner
Transform
0.1s -
✓
Draft the digest
Agent step
Ran with 4 tools, returned a structured summary
6.2s -
Approve the digest
Needs approval
Assigned to Michael Brennan
Approve Deny -
Post the digest
Sprinto
Queued
Collections and dashboards
Sprinto health numbers refresh without being asked.
Four metrics, 14 days of risks created and a team breakdown, computed with no model.
Sprinto health
Refreshed 4 minutes ago · every 15 minutes · from the controls collection
Controls
1,284 ↓ 12%
Policies
96 ↓ 8%
Needs attention
3 ↑ 2
Updated this week
412 ↑ 9%
Controls created
Last 14 days
By team
Share of activity
Security 34%
Compliance 27%
People Ops 21%
Procurement 18%
Related connectors
More from the catalog
FAQ
Frequently asked questions
How do I connect Sprinto to Claude?
Connect Sprinto in Elaichi first: you sign in to Sprinto over OAuth, approve the access it asks for, and the connection is live. There is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude signs in to Elaichi and Sprinto appears in its tool list.
Does Sprinto work with ChatGPT and Cursor as well as Claude?
Yes. Once Sprinto is connected in Elaichi, Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent all use the same endpoint, https://api.elaichi.ai/mcp. You connect Sprinto once and every client picks it up.
What can an AI agent actually do with my Sprinto data?
It can check your compliance status, controls, audits, policies, vendors and risks in Sprinto and answer questions about them in plain language. It can also take actions, such as creating a risk, updating a policy or onboarding a new US staff member. Short, specific asks work best, for example which controls are failing this week, rather than a long paragraph.
Does connecting Sprinto give the AI everything in my workspace?
No. Every call to Sprinto runs as the person who signed in, so the AI sees only the controls, audits, vendors and risks that person can already see in Sprinto. Elaichi can narrow that access further with restrictions, and it can never widen it beyond what Sprinto itself allows.
Can I stop an agent from deleting or changing things in Sprinto?
Yes. Restrictions in Elaichi work per action, so you can allow reading controls and audits in Sprinto while blocking anything that updates a policy or creates a risk. A restricted action is left out of the AI client's tool list entirely, so it cannot be called no matter what the prompt says.
What happens to a Sprinto connection when someone leaves?
Offboarding that person in Elaichi ends their access to Sprinto through every AI client at once. A connection they shared with a team keeps working for everyone else. If you want Sprinto gone entirely, disconnect it once in Elaichi and it disappears from Claude, ChatGPT, Cursor and every other client.
Does the Sprinto MCP connector work with Gemini, Codex, Claude Code or other MCP clients?
Yes. Sprinto is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.
Is Elaichi an alternative to Zapier MCP for Sprinto?
Yes. Both let Claude, ChatGPT or Cursor use Sprinto. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Sprinto call.
How is Elaichi different from Composio for Sprinto?
Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Sprinto: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.
Put Sprinto in front of your team
14 days on Gold, no credit card. Connect it once and pick what each team can call.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.