# Cakewalk MCP connector

The Cakewalk connector brings your work apps, user groups, access requests and policies into Claude, ChatGPT, Cursor and other AI clients, so your team can review access, approve requests and deactivate leavers by asking in plain language.

Source: https://elaichi.ai/connectors/cakewalk/

## Facts

| | |
| --- | --- |
| Application | Cakewalk |
| Category | Compliance |
| AI tools | 25 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | Yes |

## What you can ask once Cakewalk is connected

- List Cakewalk users in the Finance group.
- Which work apps are hidden for the Contractors group?
- Show work app accesses created in Cakewalk this week.

## Connect Cakewalk in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Cakewalk.
2. Optionally set Share with, then press Connect.
3. Paste a Cakewalk API key. One person generates a token in Cakewalk and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Cakewalk tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Cakewalk to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Cakewalk to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Cakewalk to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Cakewalk to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Cakewalk tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Cakewalk through Elaichi

### Clear the access request queue from chat

IT. Ask which Cakewalk tasks are waiting, hear who asked for what, and approve or decline each request without opening the admin console.

### Deactivate a leaver and remove group access

Security. When someone leaves, deactivate their Cakewalk user and pull them out of the user groups that grant work apps, all in one conversation.

### Pull an access list for the auditor

Compliance. Ask who has access to a given work app, at which permission level, and which policy governs it, then hand the auditor a ready answer.

### Set up a new hire's apps on day one

People. Add the new starter to the right Cakewalk user group and grant the group's default work apps in one go instead of app by app.

### Update app policies and permission levels

IT. Tighten the policy on a work app or change what a permission level allows, and record the reason in a custom field while you are there.

### Check who holds seats in costly apps

Finance. List every access on an expensive work app, compare it to the people in the group who should have it, and flag seats to reclaim.

## Frequently asked questions

### How do I connect Cakewalk to Claude?

Two steps. First, connect Cakewalk in Elaichi by pasting your Cakewalk API key when prompted; there is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Sign in and your Cakewalk work apps, groups and tasks are available in the conversation.

### Does Cakewalk work with ChatGPT and Cursor as well as Claude?

Yes. Once Cakewalk is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, is added to Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Cakewalk once and every client uses it.

### What can an AI agent actually do with my Cakewalk data?

With Cakewalk connected, an agent can list your users and user groups, show which work apps a group gets by default and which are hidden, and tell you who has access to an app and at what permission level. It can approve or decline pending access tasks, add or remove people from groups, deactivate a user, grant accesses in bulk, and update a work app's policy, permission level policy or custom fields.

### Does connecting Cakewalk give the AI access to every app and policy in my workspace?

No. Access follows the person who signed in, so the agent sees and changes only what that person's Cakewalk API key already allows. Elaichi can narrow that further, for example to read-only review of accesses and policies, but it can never widen what Cakewalk itself permits.

### Can my team share one Cakewalk connection?

Yes. One administrator connects Cakewalk in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so every approval, group change or deactivation in the audit log names the person who did it.

### Can I stop an agent from deactivating users or changing policies in Cakewalk?

Yes. Restrictions in Elaichi work per action, so you can allow listing users, groups and accesses while blocking deactivation, group removals or policy updates in Cakewalk. A blocked action is never advertised to Claude, ChatGPT or Cursor at all, so no prompt, however worded, can reach it.

### What happens to a Cakewalk connection when someone leaves?

Offboarding that person in Elaichi ends their access to Cakewalk through every AI client at once. If they had connected a shared Cakewalk connection, it keeps working for everyone else on the team. When you do want it gone, disconnecting Cakewalk once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client together.

## All 25 Cakewalk tools

Every tool below is callable through https://api.elaichi.ai/mcp once Cakewalk is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Cakewalk users** (List). List Cakewalk users. Returns a paginated list of simplified user profiles including id, name, email, and statusName.
- **Cakewalk users deactivate** (Deactivate). Deactivate a specific Cakewalk user by id. Required: id.
- **Get single Cakewalk user by ID** (Get). Get detailed information about a specific Cakewalk user by id. Returns: id, name, email, roleName, statusName, lastLogin, and managerId.
- **List all Cakewalk users groups** (List). List all users groups in Cakewalk. Returns a paginated list of simplified group objects including id, name, description, isIdpGroup, and isReadOnly.
- **Get single Cakewalk users group by ID** (Get). Get detailed information about a specific Cakewalk users group by id. Returns: id, name, description, isIdpGroup, isReadOnly, numberOfUsers, numberOfDefaultWorkApps, and numberOfHiddenWorkApps. Required: id.
- **List all Cakewalk users group default work apps** (List). List default work apps associated with a users group in Cakewalk. Returns each entry's workApp (id, name, statusName) and optional permissionLevel (id, name, description). Required: users_group_id.
- **List all Cakewalk users group hidden work apps** (List). List hidden work apps associated with a specific users group in cakewalk. Returns the collection of hidden work app records. Required: users_group_id.
- **List all Cakewalk users group users** (List). List users belonging to a Cakewalk users group. Returns the collection of users in the group. Required: users_group_id.
- **Create a Cakewalk users group user** (Create). Add one or more users to a Cakewalk users group. Returns a 201 Created response on success. Required: users_group_id, userIds, and triggeredByUserId.
- **Delete a Cakewalk users group user by ID** (Delete). Remove a user from a Cakewalk users group. Returns an empty response on success. Required: users_group_id and id.
- **List all Cakewalk work apps** (List). List all available Work Apps in Cakewalk. Returns: id, name, statusName for each work app.
- **Get single Cakewalk work app by ID** (Get). Get detailed information about a specific Cakewalk Work App by id. Returns: id, name, statusName, categoryName, url, imageUrl, tagLine, description, owner, numberOfAccounts, serverLocations, certifications, and aiRisk. Required: id.
- **List all Cakewalk work app accesses** (List). List user accesses for a specific Cakewalk Work App. Returns: isOwner, user (id, name, email, roleName, statusName), permissionLevel, and lastAccessedAt per access entry. Required: work_app_id.
- **Cakewalk work app accesses bulk create** (Create). Create user access entries for one or more Cakewalk Work Apps in a single bulk request. Returns an empty 201 response on success. Required: data array where each entry requires workAppId and userId.
- **List all Cakewalk work app permission levels** (List). List permission levels for a specific Work App in Cakewalk. Returns the available permission level records associated with the given work app. Required: work_app_id.
- **Update a Cakewalk work app policy by ID** (Update). Update the policy assigned to a Cakewalk Work App for a specific request type. Returns an empty 204 response on success. Required: work_app_id (Work App identifier), id (request type: GrantAccessRequest, RemoveAccessRequest, ArchiveWorkAppRequest, ChangePermissionLevelRequest, or AddNewManagedWorkAppRequest), and policyId in the body.
- **Update a Cakewalk work app permission level policy by ID** (Update). Update the policy assigned to a specific permission level within a Cakewalk Work App for a given request type. Returns an empty 204 response on success. Required: work_app_id, permission_level_id, id (request type), and policyId.
- **List all Cakewalk work app custom fields** (List). List all custom fields for a specific Cakewalk Work App. Returns: id, name, type, required, value, guidValue. Required: work_app_id.
- **Update a Cakewalk work app custom field by ID** (Update). Partially update custom fields for a specific Cakewalk Work App. Required: work_app_id.
- **List all Cakewalk tasks** (List). List Cakewalk tasks for a specific user, optionally filtered by task status. Returns: id, type, status, createdAt, lastUpdatedAt, assignedUserId per task. Required: userId.
- **Get single Cakewalk task by ID** (Get). Get detailed information about a specific Cakewalk task by id. Returns: id, type, status, createdAt, lastUpdatedAt, assignedUser, claimers, executedByUser, request, and review metadata. Required: id.
- **Create a Cakewalk task approval** (Create). Approve a task in cakewalk by submitting an approval action against the specified task. Required: task_id.
- **Create a Cakewalk task decline** (Create). Decline a task in cakewalk. Required: task_id.
- **List all Cakewalk policies** (List). List compatible policy templates for a specific request type in cakewalk (e.g., access or remove). Returns policy templates including their logic, conditions, and approval flow definitions. Required: id (the request type).
- **Create a Cakewalk access review** (Create). Create an access review campaign in cakewalk to audit and certify user access across specific apps or all apps. Defines the campaign scope, assignees (such as app owners, line managers, or a review owner), and completion deadline.
