# Connect Elaichi to Claude

> To connect Elaichi to Claude, add one URL as a custom connector and sign in with OAuth. On Team and Enterprise, an Owner adds it once for everyone.

**TL;DR** To connect Elaichi to Claude, add Elaichi's one organization-wide MCP endpoint, https://api.elaichi.ai/mcp, as a custom connector and sign in with OAuth. On Team and Enterprise, an Owner adds it once under Organization settings and each member connects it under Customize. Pro and Max users add it themselves, and Free allows one custom connector. After sign-in, the member's role, what is shared with them and any restrictions decide which tools Claude can call.

## How do I connect Elaichi to Claude?

Add one URL, `https://api.elaichi.ai/mcp`, as a custom connector, then sign in with OAuth. To connect Elaichi to Claude on Team or Enterprise, an Owner adds the connector once and each member connects it. On Pro and Max you do both yourself. There is no API key to paste and no server to run.

A company's Claude rollout usually starts with one team asking for one app. The second request is a different app, and the third comes from someone who should only read. Adding each app's own connector means one setup per app, each with its own permissions model. One Elaichi connector covers every app the company connects, with one set of rules.

MCP (Model Context Protocol) is the standard way an AI assistant calls tools in other apps, and the [specification](https://modelcontextprotocol.io/specification/2026-07-28) is public. Elaichi serves every connected SaaS account through one organization-wide endpoint, `POST /mcp`, behind OAuth.

## Which Claude plans allow a custom connector?

All five. Anthropic's help center lists custom connectors on Free, Pro, Max, Team and Enterprise, in Claude on the web, Claude Desktop and Cowork, and limits Free to one custom connector ([Anthropic's guide to custom connectors](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp), checked October 2026).

Who adds it differs by plan. On Team and Enterprise, an Owner or Primary Owner adds custom connectors for the whole organization. Enterprise also lets a custom role that manages the organization's libraries add one ([Anthropic's connector docs](https://claude.com/docs/connectors/custom/add-unlisted)). Everyone else asks an Owner.

## How does a Team or Enterprise Owner add the connector?

Once, for everyone, in the organization's settings. As of October 2026 the path is:

1. Open **Organization settings**, then **Connectors**.
2. Select **Add**, hover over **Custom**, and choose **Web**.
3. Paste `https://api.elaichi.ai/mcp` as the server URL.
4. Leave **Advanced settings** empty, and select **Add**.

Then each member opens **Customize**, then **Connectors**, finds the Elaichi connector, which usually carries a Custom label, and selects **Connect**. That sign-in is theirs alone. Nobody shares a credential, and what each member can reach is decided by their own role in Elaichi.

## How do you add it on Pro, Max or Free?

From your own settings, in one pass. Open **Customize**, then **Connectors**, select the **+** button, then **Add custom connector**. Paste the URL, leave the advanced settings empty, and select **Add**. Anthropic gives these steps for Pro and Max, and Free plans can add one custom connector.

The advanced settings take an OAuth client ID and secret, and Elaichi needs neither. Anthropic's authentication docs say Claude uses a client ID metadata document only when the server advertises one, and otherwise falls back to dynamic client registration ([how Claude authenticates connectors](https://claude.com/docs/connectors/building/authentication)). Elaichi advertises no metadata document and supports registration under [RFC 7591](https://www.rfc-editor.org/rfc/rfc7591), so Claude registers itself.

## Which address do you paste, exactly?

`https://api.elaichi.ai/mcp`, with no trailing slash, on the `api` host. That address answers an unsigned request with the challenge that starts sign-in. Two near misses do not.

- With a trailing slash, `https://api.elaichi.ai/mcp/` returns 404.
- On the app host, `https://app.elaichi.ai/mcp` returns 405.

Neither carries the challenge, so Claude never reaches Elaichi's sign-in, and the connector looks broken for no visible reason. If sign-in never opens, check the URL first. [Fixing OAuth errors when adding an MCP connector](/blog/mcp-oauth-errors/) covers what to do when the sign-in itself fails.

## What will Elaichi's consent screen ask you?

Which organization, and what the connector may do. If you belong to one organization, it is chosen for you. If you belong to several, nothing is preselected, and the one you pick is the only one Claude will see. Changing it later means connecting again.

The permissions arrive as up to four checkboxes:

- **Read your organization's data**
- **Create and change data**
- **Run your connected tools**
- **Delete data and remove access**

Everything Claude requested starts ticked except delete, which never does. Untick anything the person should not have. With **Run your connected tools** ticked, a second step asks which toolboxes Claude may use: **All my tools**, the default, or only the ones you pick.

## How do Claude's tool permissions apply to Elaichi?

They apply to Elaichi's two discovery tools, not to each app's tools. In Elaichi, connected tools are never listed one by one, however few there are. Claude finds a tool with `search_tools` and runs it with `execute_tool`.

Claude lets you set each connector's tools to Always allow, Needs approval or Blocked, and its chat prompt offers Allow once or Always allow ([Anthropic's getting-started guide](https://claude.com/docs/connectors/getting-started)). Because every connected tool runs through `execute_tool`, a permission on it covers every app at once. Leave it on Needs approval if you want a prompt before each call, and put the per-tool decisions in Elaichi's restrictions, which can tell a Jira read from a Jira delete.

## Where does Claude connect from?

From Anthropic's servers, not the user's machine. The help center says Claude reaches a custom connector "from Anthropic's cloud infrastructure, rather than from your local device", on every Claude client. Elaichi's endpoint is public, so there is nothing to allowlist on your network for it.

The SaaS accounts are reached by Elaichi, not by Claude. A member connects each account once, from a catalog of 500+ connectors that Elaichi authors and serves. A separate credential service holds each account's secrets, encrypted at rest, and marks a connection `needs_reauth` when a refresh fails.

## Does a member have to switch Elaichi on in each chat?

There is a switch per conversation. Under the chat's **+** button, then **Connectors**, each connector has a toggle that decides whether Claude may use it in that conversation. Turning it off does not disconnect anything: Claude stays signed in, and the toggle can come back on in any chat.

If Elaichi's tools seem to vanish in one conversation, check that toggle before anything else. If they are missing everywhere, [MCP tools not showing up? Start here](/blog/mcp-tools-not-showing/) walks the checks in order.

## What limits what Claude can do through Elaichi?

The member's role, what has been shared with them, and restrictions, checked on every call. Restrictions decide which connectors and which individual tools a target may reach. In Elaichi, restriction targets are role or user only; the organization default is the absence of a rule, which means allow everything. A rule on a user replaces the role rules for that user rather than adding to them.

Frozen arguments pin a value the model must not choose, such as the workspace a team writes to. One condition: a freeze binds only calls made through its toolbox entry, so share the toolbox with the people it governs, not the connection itself. A role or restriction change takes about two minutes to apply, so test a new rule after that window, not straight away.

Elaichi records each call in the audit trail. It writes one entry per tool-call attempt, succeeded or failed, naming the account the call reached, and [what an AI agent audit log must capture](/blog/what-an-ai-audit-log-must-capture/) lists the fields.

## How do you take Claude access away from someone?

Remove or suspend them in Elaichi, and their next request from Claude fails. In Elaichi, removing or suspending a member revokes every live grant in the same transaction as the membership change. A person can also disconnect Claude under **Settings**, then **Connected apps**, in Elaichi, which ends that one grant.

Disconnecting inside Claude signs Claude out of the connector, and the row then offers Connect again. To be sure the access is gone, end it on Elaichi's side. [Offboarding AI access, contractors included](/blog/offboarding-when-the-agent-holds-access/) covers the rest of a departure.

## When is Claude's own connector for an app enough?

When one team needs one app and that app's own connector does what you need. Claude's connector directory lists connectors from many vendors. If a team needs only one of them, with that vendor's permissions and nothing across apps, use it. [When you don't need an MCP gateway yet](/blog/when-you-dont-need-an-mcp-gateway/) lists the signals that change the answer.

Elaichi's Gold plan is $15 per user per month in USD, and your region's price is on the [pricing page](/pricing/). Gold starts with a 14-day trial, no credit card to start. Checkout does collect a card, and it sets the paid trial to the remaining days rather than granting a fresh 14, so it is one continuous trial rather than two.

The same address serves the company's other clients: [the ChatGPT setup](/blog/connect-elaichi-to-chatgpt/) and [the Cursor setup](/blog/cursor-mcp-one-endpoint-vs-per-developer/) use it unchanged. To choose a first team, start from the [connector catalog](/connectors/).

## FAQ

### Which Claude plans can connect to Elaichi?

Free, Pro, Max, Team and Enterprise can all add a custom connector, in Claude on the web, Claude Desktop and Cowork. Free is limited to one custom connector. On Team and Enterprise, an Owner or Primary Owner adds it for the organization, and members then connect it themselves.

### Do I need an OAuth client ID to connect Elaichi to Claude?

No. Leave the advanced settings empty. Elaichi supports dynamic client registration and publishes no client ID metadata document, so Claude registers itself and each person signs in with their own identity.

### Why does Claude list only a few Elaichi tools?

In Elaichi, connected tools are never listed one by one, however few there are. Claude finds a connected tool with search_tools and runs it with execute_tool, so a short list in the connector's settings is the expected view.

### How do I stop someone using Elaichi from Claude?

Remove or suspend them in Elaichi. In Elaichi, removing or suspending a member revokes every live grant in the same transaction as the membership change, so their next request from Claude fails. A person can also disconnect the app under Settings, then Connected apps, which ends that grant.

## Read next

- [Connect company apps to Claude and ChatGPT](/blog/connect-company-apps-to-claude-and-chatgpt/) — To connect company apps to Claude and ChatGPT, connect each account once in Elaichi, share it, and add one URL to both. No MCP server to run.
- [Connect Elaichi to Claude Code](/blog/connect-elaichi-to-claude-code/) — To connect Elaichi to Claude Code, run one claude mcp add command and sign in with OAuth. The entry holds no secret, so a project .mcp.json is safe to commit.
- [Connect Elaichi to Codex](/blog/connect-elaichi-to-codex/) — To connect Elaichi to Codex, add one URL as a streamable HTTP server and run codex mcp login. No token, no header, and each engineer signs in as themselves.
