# Codefresh MCP connector

The Codefresh connector brings Codefresh accounts, users, access rules and analytics reports to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person can ask questions and make changes under their own Codefresh access.

Source: https://elaichi.ai/connectors/codefresh/

## Facts

| | |
| --- | --- |
| Application | Codefresh |
| Category | CI |
| AI tools | 410 |
| Authentication | Connects with an API key |
| Bring your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Codefresh is connected

- List every Codefresh admin and when they were added
- Which access rules give the payments team write access?
- Summarize last week's Codefresh analytics reports for the standup

## Connect Codefresh in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Codefresh.
2. Optionally set Share with, then press Connect.
3. Paste a Codefresh API key. One person generates a token in Codefresh and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Codefresh tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Codefresh MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Codefresh MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Codefresh MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Codefresh to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Codefresh tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Codefresh through Elaichi

### Audit who can touch which pipelines

Platform engineering. Ask for every access rule in Codefresh, see which team each one grants access to, and tighten the ones that reach too far.

### Onboard a new engineer in one ask

DevOps. Add the engineer to the Codefresh account, resend the invite if it was missed, and attach the right team rule without opening the admin console.

### Review admin accounts before a quarterly check

Security. List every Codefresh admin, spot the people who no longer need that level of access, and remove them in one batch.

### Pull build analytics into Monday's standup

Engineering management. Read the analytics reports Codefresh already produces and get a short summary of how the week went, ready to paste into the standup notes.

### Clean up accounts after a reorg

IT. Find Codefresh accounts that belonged to teams that no longer exist and delete them together, with each removal recorded in the audit log.

### See which GitHub Actions are in use

Developer experience. List the GitHub Actions and their contexts in Codefresh to understand what pipelines depend on before a migration or a cleanup.

## Elaichi vs Zapier MCP vs Composio for Codefresh

All three can connect Codefresh to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Codefresh tools | Allow or restrict single Codefresh tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Codefresh call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Codefresh to Claude?

Connect Codefresh in Elaichi first: paste a Codefresh API key when asked, and the connection is live. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. There is no OAuth application to register in Codefresh and no client ID or secret to generate.

### Does Codefresh work with ChatGPT and Cursor as well as Claude?

Yes. Once Codefresh is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Codefresh once and every client picks it up.

### What can an AI agent actually do with my Codefresh data?

It can list and explain Codefresh access rules and tags rules, add or update users and admins, resend invites, read analytics reports, and show which GitHub Actions are set up. You ask in plain language, and short concrete asks like "list every Codefresh admin" work better than long paragraphs. Anything it changes shows up in the audit log under your name.

### Does connecting Codefresh give the AI everything in my Codefresh account?

No. Every call runs inside the Codefresh access of the person who signed in, so the agent sees and changes only what that person already could. Elaichi can narrow that further with restrictions, and it never widens it.

### Can my team share one Codefresh connection?

Yes. One person connects Codefresh in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every Codefresh change.

### Can I stop an agent from deleting or changing things in Codefresh?

Yes. Restrictions in Elaichi work per action, so you can allow reading Codefresh access rules and analytics reports while blocking deletes of accounts or admins. A restricted action is never advertised to the AI client at all, so no prompt can reach it.

### What happens to a Codefresh connection when someone leaves?

Offboarding that person in Elaichi ends their access to Codefresh through every AI client at once. A shared Codefresh connection keeps working for everyone else on the team. If you want Codefresh gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client.

### Does the Codefresh MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Codefresh is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Codefresh?

Yes. Both let Claude, ChatGPT or Cursor use Codefresh. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Codefresh call.

### How is Elaichi different from Composio for Codefresh?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Codefresh: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 410 Codefresh tools

Every tool below is callable through https://api.elaichi.ai/mcp once Codefresh is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Codefresh abacs** (List). List the ABAC access-control rules in Codefresh. Returns a JSON object whose fields are not enumerated in the upstream spec.
- **Create a Codefresh abac** (Create). Create an ABAC access-control rule in Codefresh by posting a JSON rule definition. Returns a JSON object whose fields are not enumerated in the upstream spec.
- **Get single Codefresh abac by ID** (Get). Get a single ABAC access-control rule in Codefresh by id. Returns a JSON object whose fields are not enumerated in the upstream spec. Required: rule.
- **Codefresh abacs bulk delete** (Delete). Delete an ABAC access-control rule in Codefresh by id. Returns a JSON object whose fields are not enumerated in the upstream spec. Required: rule.
- **Delete a Codefresh abac batch by ID** (Delete). Create or delete Codefresh ABAC permission rules in a single batch. Returns a JSON response object (upstream documents no field breakdown for it). Requires a request body containing a create array of rule definitions (teams, actions, resource, relatedResource, tags) and/or a delete array of rule ids.
- **List all Codefresh abac resources** (List). Get the ABAC rules defined for a specific resource in Codefresh. Returns the matching rules as an opaque JSON object (field structure not documented upstream). Required: resource.
- **Update a Codefresh tags rule by ID** (Update). Update the tags assigned to a Codefresh ABAC rule. Returns a JSON object response confirming the update. Required: rule.
- **Create a Codefresh tags rule** (Create). Create tags for one or more Codefresh ABAC rules in a single call. Sends a JSON body with tags and rules arrays and returns a JSON object response confirming the tag assignment.
- **Get single Codefresh abac team by ID** (Get). Get the ABAC rules assigned to a team in Codefresh by team id. Returns the team's rules payload as a JSON object; the upstream API documents the response only as a JSON object and does not enumerate the individual rule fields. Required: id.
- **Create a Codefresh abac team rule** (Create). Create ABAC team rules in batch in Codefresh, applying the same resource, relatedResource, actions, and tags to multiple teams in one call. Returns a JSON object; the upstream API does not enumerate the response fields. Requires a JSON request body with teams, actions, resource, relatedResource, and tags.
- **List all Codefresh github actions** (List). List GitHub actions in Codefresh matching a search query by name. Returns matching records with an id and action-specific attributes. Required: text.
- **Get single Codefresh github action context by ID** (Get). Get the github action context for a specific github action in Codefresh by id. Returns the context as an opaque JSON object; the API spec does not document its individual fields. Required: id.
- **List all Codefresh analytics reports** (List). Get an analytics report by name from the Codefresh Analytics API. Returns a JSON payload whose fields are report-specific and vary by report name.g. creditConsumption, pipelineCreditConsumption, activeCommitters). Supported granularity and date-range windows differ per report; omit granularity for aggregated totals. Required: report_name.
- **List all Codefresh analytics metadata** (List). List analytics metadata in Codefresh — the discovery endpoint for Platform Analytics, returning the reports available through the reports endpoint and the parameters each supports. Returns the metadata as a generic JSON object whose structure is not publicly enumerated upstream; report names, supported granularities, and time ranges vary per report.
- **List all Codefresh etl type last success times** (List). Get the last successful run time for an analytics ETL type in Codefresh. Returns a JSON object describing the last successful ETL time for the requested type.
- **Delete a Codefresh account by ID** (Delete). Request deletion of a Codefresh account by id. Returns an untyped JSON object whose fields the upstream documentation does not enumerate. Required: id.
- **Codefresh accounts bulk delete** (Delete). Remove a user from a Codefresh account by account_id and user_id. Returns an untyped JSON object whose fields the upstream documentation does not enumerate. Documented upstream as not yet implemented. Required: account_id, user_id.
- **Create a Codefresh resend invite** (Create). Resend a Codefresh account invite email to a user. Returns a JSON object confirming the resend on success (the upstream spec does not enumerate its fields). Required: account_id, user_id.
- **Create a Codefresh adduser** (Create). Add existing user to account. Required: account_id, user_id.
- **Create a Codefresh admin** (Create). Set a user as an admin of a Codefresh account. Returns a JSON object; Codefresh documents the response as an untyped object and does not enumerate its fields. Required: account_id, user_id.
- **Codefresh admins bulk delete** (Delete). Remove a user's admin role from a Codefresh account. Returns a JSON object; Codefresh documents the response as an untyped object and does not enumerate its fields. Required: account_id, user_id.
- **Create a Codefresh account adduser** (Create). Add a user to a Codefresh account, specifying the user by email address or an existing Codefresh user name. Returns a JSON object response; the upstream API does not enumerate the returned fields. Required: account_id.
- **Create a Codefresh account update** (Create). Update the public settings of a Codefresh account, sending a settings object with integration configuration and notification entries (webhook or Slack). Returns a JSON object; the upstream does not document its fields. The upstream marks this settings schema as still being defined. Required: account_id.
- **Create a Codefresh updateuser** (Create). Update user details for a user in a Codefresh account. Returns the updated user object as JSON. Required: account_id, user_id.
- **List all Codefresh account users** (List). List users of a Codefresh account by its id. Returns the account's users as a JSON object; the upstream docs do not enumerate the response fields. Required: account_id.
- **List all Codefresh account settings** (List). Get the Codefresh account settings. Returns: schemaVersion, updatedAt, settings.
- **Update a Codefresh account setting by ID** (Update). Update the Codefresh account settings. Returns the updated account settings object: schemaVersion, updatedAt, settings.
- **List all Codefresh admin accounts** (List). List all Codefresh accounts in the system. Returns each account with its id, name, and provider.
- **Create a Codefresh admin account** (Create). Create a new account in Codefresh. Returns the created account with its id, name, and provider. Required: name.
- **Get single Codefresh admin account by ID** (Get). Get a single Codefresh account by id. Returns the account object with its id, name, and provider. Required: id.
- **Delete a Codefresh admin account by ID** (Delete). Delete a Codefresh account by id. Returns an empty 204 response on success. The upstream API lists this endpoint as not yet implemented. Required: id.
- **List all Codefresh archive lists** (List). List entries from the Codefresh account archive via the admin API. Returns a JSON object; the upstream documentation does not enumerate its fields.
- **Create a Codefresh accounts addpendinguser** (Create). Add a pending user without an account in Codefresh. Returns a JSON object that includes _id. Required: provider, userName.
- **Create a Codefresh account segment** (Create). Set the account segment for a Codefresh account, supplying the segment payload (e.g. trial details such as trialing, trialStart, trialEnd). Returns: a JSON object on success (the upstream spec does not enumerate its response fields). Required: account_id, segment_type.
- **Create a Codefresh account rename** (Create). Rename a Codefresh account via the admin API. Returns a JSON object on success; the upstream API does not document the response fields. Required: account_id.
- **List all Codefresh admin runtime environments** (List). List Codefresh admin runtime environments. Returns one record per environment, including its name plus a free-form attributes object holding the remaining runtime-environment fields (not enumerated upstream).
- **Get single Codefresh admin runtime environment by ID** (Get). Get a Codefresh admin runtime environment by id (its runtime environment name, e.g. 'my-aws-runner/cf'). Returns the record's name plus a free-form attributes object holding the remaining runtime-environment fields (not enumerated upstream). Required: id.
- **Delete a Codefresh admin runtime environment by ID** (Delete). Delete a Codefresh admin runtime environment by id (its runtime environment name). Returns an unspecified JSON object on success; the upstream docs do not enumerate its fields. Required: id.
- **Codefresh admin runtime environments set default** (Set). Set the default Codefresh admin runtime environment for a plan. Returns the record's name plus a free-form attributes object holding the remaining runtime-environment fields (not enumerated upstream). Required: plan, runtime_environment_name.
- **Update a Codefresh admin runtime environment by ID** (Update). Update (upsert) a Codefresh admin runtime environment by id (its runtime environment name) with a JSON request body. Returns the record's name plus a free-form attributes object holding the remaining runtime-environment fields (not enumerated upstream). Required: id.
- **List all Codefresh runtime environments accounts** (List). List runtime environments associated with a Codefresh account, optionally filtered by account ids. Returns a JSON object whose fields are not enumerated in the upstream spec. Required: account.
- **Codefresh runtime environments accounts bulk update** (Update). Set the default runtime environment for a Codefresh account by runtime environment name. Returns a JSON object whose fields are not enumerated in the upstream spec. Required: account, runtime_environment_name.
- **Codefresh account modifies bulk update** (Update). Add a runtime environment to the Codefresh account, identified by its runtime environment name. Returns a JSON response object; the upstream spec does not document its fields. Required: runtime_environment_name.
- **Codefresh account modifies bulk delete** (Delete). Remove a runtime environment from the Codefresh account, identified by its runtime environment name. Returns a JSON response object; the upstream spec does not document its fields. Required: runtime_environment_name.
- **Create a Codefresh runtime environments health check** (Create). Submit a health-check report from a runtime environment cluster to Codefresh. Returns a generic JSON object acknowledgment whose fields are not documented upstream.
- **Codefresh admin users activate** (Activate). Activate a Codefresh admin user by id. Returns an unenumerated JSON object on success (the upstream API spec does not document the response fields). Required: user_id.
- **Codefresh admin users bulk delete** (Delete). Delete a Codefresh admin user by user name. Returns an unenumerated JSON object on success (the upstream API spec does not document the response fields). Required: user_name.
- **Create a Codefresh user admin role** (Create). Change the admin role assigned to a Codefresh user. Returns a JSON object; the upstream API does not enumerate the fields of this response. The request body identifies the target user by its _id and userName.
- **Create a Codefresh user account** (Create). Change the account settings for a Codefresh user via the admin API. Returns a JSON object on success; the upstream API specification does not enumerate its fields.
- **List all Codefresh user login as users** (List). Log in to Codefresh as another user by supplying their user id (admin operation). Returns an opaque 200 JSON response; the API documents no specific fields for this response.
- ...and 360 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
