Connectors / SSO
SSO MCP connectors for Claude, ChatGPT and Cursor
5+ SSO connectors in the catalog, each behind the same governed MCP endpoint as everything else in Elaichi.
https://api.elaichi.ai/mcp
The same for every user.
-
Their own access. An agent never gets more than the person it acts for.
-
One connection, every client. Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent.
The connectors
SSO connectors in the catalog
Connect one and your whole team reaches it, each inside the access they already have, without anyone handling a credential.
6 connectors
-
Auth0 Hosted sign-in 466 tools
-
Google Hosted sign-in 120 tools
-
Google Workspace
Hosted sign-in
21
tools
-
Okta Bring your own OAuth app 318 tools
-
Torii Hosted sign-in 26 tools
-
World Hosted sign-in 31 tools
No SSO connector by that name
It may sit under another category, or not be in the catalog yet — any documented API can become a connector.
In practice
What teams do with SSO connectors
Drawn from the connector pages in this category, so every line describes something one of these connectors actually does.
IT
-
Set up a new hire in Auth0
Create the user, attach the right role, and add them to their organization in one request instead of clicking through three screens.
-
Set up a new hire on day one
Create the Okta user, add them to the right groups, and confirm which applications they can now reach, all from one request.
-
Check who still uses an app before renewal
Ask which people are assigned to a given application in Torii and how many of them are still active, so the renewal conversation starts with real numbers instead of a guess.
Security
-
Review admin roles and third-party tokens
List every role and who holds it, flag super admin assignments that should not exist, and see which outside apps have tokens granted by your users.
-
Review who holds an admin role
List every role, see which permissions each one grants, and spot accounts that carry more access than their job needs.
-
Review who holds admin roles
List every Okta role and who is assigned to it, then flag accounts that hold more than the job needs.
Support
-
Find the right help doc without digging
Ask for the Google Doc that covers a refund or setup question and get the current version from Drive, instead of scrolling through shared folders.
-
Find out why a verification failed
When a user says they could not prove they are human, pull up their verification and the precheck result to see what went wrong before you reply.
-
Check why a customer cannot log in
Pull up a user by email, read their recent login logs, and see which permissions they hold before replying to the ticket.
Operations
-
Read survey results without opening the spreadsheet
Ask what people said in a Google Form, such as an office move survey or a vendor intake, and get the responses grouped and summarized.
-
Help someone recover their account
Start, execute or cancel a recovery for a user who lost their device, and add or remove authenticators once they are back in.
-
Pull usage reports for the quarterly review
Gather Google Workspace usage reports by org unit and turn them into a short summary of who is active and where adoption is thin.
Once it is connected
Things to ask
Each of these is answered against the access the person asking already has, in the SSO account you connected.
-
List Auth0 users who gained the admin role this week.
-
Summarize the responses to last week's onboarding form.
-
List all Google Workspace groups with no members.
-
Which Okta users were deactivated in the last week?
-
List Torii applications with no active users this quarter.
-
How many World verifies completed for the onboarding action?
The tools
What an agent can call in SSO
- Connectors
- 5+
- Tools
- 982
- Hosted sign-in
- 5
in the SSO catalog
callable the moment you connect
connect with nothing to register
Of those 982 tools, 10% delete something. Restricting an agent to reads is not a promise here, it is 431 tools admitted and the rest left out — and a restricted tool is never advertised to the model at all.
- Read 44%
- 431 tools · list, get, search
- Write 29%
- 286 tools · create, update, send
- Delete 10%
- 98 tools · delete, remove, archive
- Other 17%
- 167 tools · vendor-specific verbs
One endpoint
https://api.elaichi.ai/mcp
Every connector above answers here.
Every SSO connector, by depth
Tool counts are what the connector exposes today; the split is what those tools do.
Hosted sign-in takes a partnership with each vendor, and more are in progress. Until one lands, Your own app means the connector works today — you register an OAuth app once and connect.
FAQ
Frequently asked questions
How many SSO connectors does Elaichi have?
5+ SSO connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.
Can Claude, ChatGPT and Cursor all use SSO connectors?
Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor, any MCP client and the Elaichi Agent all connect to that same address with OAuth. Connecting a SSO account once makes it reachable from every one of them.
Do SSO connectors work with Gemini, Codex, Claude Code or other MCP clients?
Yes. SSO connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.
Do SSO connectors need me to bring my own OAuth app?
Most do not. 5 of the SSO connectors use Elaichi's hosted sign-in, with nothing to register. The other 1 ask you to bring your own OAuth app: you register it once with the vendor and connect. Hosted sign-in for those is in progress, a vendor partnership at a time, and when one lands the only thing that changes is that the registration step goes away. Each connector's page says which it is before you start.
Can I stop an agent from writing to SSO tools?
Yes. Tool restrictions apply at role and individual level, and a restricted tool is never advertised to the model, so it cannot be called or guessed at from the tool list. Read-only access to a SSO connector is a matter of allowing the reads and leaving the writes out.
Nearby
Teams that connect SSO usually connect these too
Put SSO connectors in front of your team
14 days on Gold, no credit card. Connect one and pick what each team can call.
- Works with
-
and any other MCP client, or the Elaichi Agent.
- When the trial ends
- Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.