Skip to content

Connectors / SSO

SSO MCP connectors for Claude, ChatGPT and Cursor

5+ SSO connectors in the catalog, each behind the same governed MCP endpoint as everything else in Elaichi.

https://api.elaichi.ai/mcp The same for every user.
  • Their own access. An agent never gets more than the person it acts for.

  • One connection, every client. Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent.

The connectors

SSO connectors in the catalog

Connect one and your whole team reaches it, each inside the access they already have, without anyone handling a credential.

6 connectors

Browse all 400+ connectors →

In practice

What teams do with SSO connectors

Drawn from the connector pages in this category, so every line describes something one of these connectors actually does.

IT

  • Set up a new hire in Auth0

    Create the user, attach the right role, and add them to their organization in one request instead of clicking through three screens.

  • Set up a new hire on day one

    Create the Okta user, add them to the right groups, and confirm which applications they can now reach, all from one request.

  • Check who still uses an app before renewal

    Ask which people are assigned to a given application in Torii and how many of them are still active, so the renewal conversation starts with real numbers instead of a guess.

Security

  • Review admin roles and third-party tokens

    List every role and who holds it, flag super admin assignments that should not exist, and see which outside apps have tokens granted by your users.

  • Review who holds an admin role

    List every role, see which permissions each one grants, and spot accounts that carry more access than their job needs.

  • Review who holds admin roles

    List every Okta role and who is assigned to it, then flag accounts that hold more than the job needs.

Support

  • Find the right help doc without digging

    Ask for the Google Doc that covers a refund or setup question and get the current version from Drive, instead of scrolling through shared folders.

  • Find out why a verification failed

    When a user says they could not prove they are human, pull up their verification and the precheck result to see what went wrong before you reply.

  • Check why a customer cannot log in

    Pull up a user by email, read their recent login logs, and see which permissions they hold before replying to the ticket.

Operations

  • Read survey results without opening the spreadsheet

    Ask what people said in a Google Form, such as an office move survey or a vendor intake, and get the responses grouped and summarized.

  • Help someone recover their account

    Start, execute or cancel a recovery for a user who lost their device, and add or remove authenticators once they are back in.

  • Pull usage reports for the quarterly review

    Gather Google Workspace usage reports by org unit and turn them into a short summary of who is active and where adoption is thin.

Once it is connected

Things to ask

Each of these is answered against the access the person asking already has, in the SSO account you connected.

  • List Auth0 users who gained the admin role this week.

    Auth0

  • Summarize the responses to last week's onboarding form.

    Google

  • List all Google Workspace groups with no members.

    Google Workspace

  • Which Okta users were deactivated in the last week?

    Okta

  • List Torii applications with no active users this quarter.

    Torii

  • How many World verifies completed for the onboarding action?

    World

The tools

What an agent can call in SSO

Connectors
5+

in the SSO catalog

Tools
982

callable the moment you connect

Hosted sign-in
5

connect with nothing to register

Of those 982 tools, 10% delete something. Restricting an agent to reads is not a promise here, it is 431 tools admitted and the rest left out — and a restricted tool is never advertised to the model at all.

Read 44%
431 tools · list, get, search
Write 29%
286 tools · create, update, send
Delete 10%
98 tools · delete, remove, archive
Other 17%
167 tools · vendor-specific verbs

One endpoint

https://api.elaichi.ai/mcp

Every connector above answers here.

Every SSO connector, by depth

Tool counts are what the connector exposes today; the split is what those tools do.

Hosted sign-in takes a partnership with each vendor, and more are in progress. Until one lands, Your own app means the connector works today — you register an OAuth app once and connect.

SSO connectors with tool counts split by read, write and delete
Connector Tools Read · write · delete Sign-in
Auth0 466 Hosted
Okta 318 Your own app
Google 120 Hosted
World 31 Hosted
Torii 26 Hosted
Google Workspace 21 Hosted

FAQ

Frequently asked questions

How many SSO connectors does Elaichi have?

5+ SSO connectors are in the catalog today, and the list grows as connectors are added. Each one arrives as a set of MCP tools an agent can call through https://api.elaichi.ai/mcp.

Can Claude, ChatGPT and Cursor all use SSO connectors?

Yes. Elaichi exposes one organization-wide endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor, any MCP client and the Elaichi Agent all connect to that same address with OAuth. Connecting a SSO account once makes it reachable from every one of them.

Do SSO connectors work with Gemini, Codex, Claude Code or other MCP clients?

Yes. SSO connectors are reached over the same MCP endpoint every client uses, so anything that speaks MCP can call them — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor and the Elaichi Agent. There is no per-client setup beyond pointing the client at https://api.elaichi.ai/mcp.

Do SSO connectors need me to bring my own OAuth app?

Most do not. 5 of the SSO connectors use Elaichi's hosted sign-in, with nothing to register. The other 1 ask you to bring your own OAuth app: you register it once with the vendor and connect. Hosted sign-in for those is in progress, a vendor partnership at a time, and when one lands the only thing that changes is that the registration step goes away. Each connector's page says which it is before you start.

Can I stop an agent from writing to SSO tools?

Yes. Tool restrictions apply at role and individual level, and a restricted tool is never advertised to the model, so it cannot be called or guessed at from the tool list. Read-only access to a SSO connector is a matter of allowing the reads and leaving the writes out.

Whose access does an agent get on a shared SSO connection?

The access of the person the agent is acting for, resolved against their current role on every call — not the access of whoever connected the account. A colleague can use a connection without ever seeing its credential.

Put SSO connectors in front of your team

14 days on Gold, no credit card. Connect one and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.