# Control Plane MCP connector

The Control Plane connector lets Claude, ChatGPT, Cursor, or any MCP client list, deploy, diagnose, restart, roll back and promote workloads across your GVCs and locations, as the signed-in person, with every call logged in Elaichi.

Source: https://elaichi.ai/connectors/control-plane/

## Facts

| | |
| --- | --- |
| Application | Control Plane |
| Category | Application Development |
| AI tools | 119 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Control Plane builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support@controlplane.com |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Control Plane is connected

- Diagnose the checkout workload in the production GVC
- Roll back the api workload to the previous version
- Add the aws-eu-central-1 location to the staging GVC

## Connect Control Plane in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Control Plane.
2. Optionally set Share with, then press Connect.
3. Approve it in Control Plane. Control Plane's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Control Plane tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Control Plane MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Control Plane MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Control Plane MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Control Plane to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Control Plane tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Control Plane through Elaichi

### Stand up a new environment for a team

Platform. Describe the environment in plain words, and the agent creates the GVC, adds the locations it should run in, and deploys the first workload. The setup follows the Control Plane rules your organization already has in place.

### Ship a build and confirm it landed

Engineering. Deploy an app to Control Plane from the chat you are already in, then ask whether the workload is healthy before telling the rest of the team.

### Diagnose a failing workload at 2am

On-call. Ask what is wrong with a workload, restart it, or roll it back to the last good version without opening the Control Plane console. The agent only touches what your own Control Plane access allows.

### Promote a workload from staging to production

Release management. Once a release has settled in staging, ask the agent to promote the workload and add a database if the new version needs one. Each step is written to the audit log with your name on it.

### Review who and what can reach a resource

Security. Pull the permissions on any Control Plane resource, check which workloads are allowed to talk to each other, and grant cloud access only where it has been approved.

### Answer platform questions straight from the docs

Developer experience. New engineers can search Control Plane documentation, rules and resource schemas in plain language, so the platform team stops answering the same question every week.

## Elaichi vs Zapier MCP vs Composio for Control Plane

All three can connect Control Plane to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Control Plane tools | Allow or restrict single Control Plane tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Control Plane call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Control Plane to Claude?

Two steps. In Elaichi, add the Control Plane connector and sign in to your Control Plane organization in the browser window that opens, approving the connection as yourself over OAuth. Then in Claude, open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. There is no OAuth application to register and no client ID or secret to generate.

### Does Control Plane work with ChatGPT and Cursor as well as Claude?

Yes. Once Control Plane is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Control Plane once and every client you use picks it up.

### What can an AI agent actually do with my Control Plane data?

With Control Plane connected, an agent can list and read your workloads, GVCs, locations and other resources, deploy an app, add a database, and diagnose, restart, roll back or promote a workload. It can also look up permissions, review which workloads can reach each other, and search Control Plane documentation and rules. Short, concrete asks such as "restart the checkout workload in production" work better than long sentences.

### Does connecting Control Plane give the AI my whole organization?

No. Every call to Control Plane runs as the person who signed in, so the agent sees only the GVCs, workloads and resources that person can already see in Control Plane. Elaichi can narrow that access further with roles and restrictions, and it can never widen it beyond what Control Plane itself allows.

### Can my team share one Control Plane connection?

Yes. One person connects Control Plane in Elaichi and shares the connection with a team, and nobody else ever handles a credential or sees the sign-in. Each teammate still signs in to Elaichi as themselves, so the audit log records who deployed, restarted or rolled back which workload.

### Can I stop an agent from deleting or changing things in Control Plane?

Yes. Restrictions in Elaichi apply per action, so you can allow reading and diagnosing Control Plane workloads while blocking deletes, rollbacks or changes to GVC locations. A restricted action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt can reach it.

### What happens to a Control Plane connection when someone leaves?

Offboarding a person in Elaichi ends their access to Control Plane through every client at once. A Control Plane connection they shared keeps working for everyone else on the team. Disconnecting Control Plane once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client together.

### Does the Control Plane MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Control Plane is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Control Plane?

Yes. Both let Claude, ChatGPT or Cursor use Control Plane. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Control Plane call.

### How is Elaichi different from Composio for Control Plane?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Control Plane: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 119 Control Plane tools

Every tool below is callable through https://api.elaichi.ai/mcp once Control Plane is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Get cpln rules** (Get). The operating guide: approval for high-impact actions, the platform facts the tools do not check, Terraform ownership, targets, CLI use, and failure handling. Optional, since the core rules arrive with every connection.
- **Get cpln skill** (Get). The runbook for one task family: how to use a feature correctly, the constraints that are easy to miss, and when it's the wrong tool. Not advertised when the AI Plugin supplies its own skills.
- **Plan app** (Action). Before any code for an app that keeps anything (content, records, files, or sign-ins): how Control Plane keeps its files, records, secrets, and replicas, and the tools that do each. The assistant settles what your request leaves open with you first. Not in `readonly`.
- **Get resource schema** (Get). The exact object schema and REST endpoints for a resource kind, for authoring an accurate manifest or calling the API.
- **Get permissions** (Get). The grantable permissions for a resource kind, for building policies.
- **Search control plane** (Search). Search the documentation: up to five hits, each with a short excerpt and its page path.
- **Query docs filesystem control plane** (Search). Read a whole docs page, or search the docs pages and OpenAPI specs, with read-only, shell-like commands.
- **List resources** (List). List resources of one kind as a summary table.
- **Get resource** (Get). Fetch one resource by kind and name, with its full JSON. Secrets return metadata only — the API never includes their data.
- **Delete resource** (Delete). Delete one resource by kind and name. The single delete tool for every deletable kind — secrets are not deletable.
- **Deploy app** (Action). Build and deploy an HTTP app: from the app files stored with `write_app_files`, a GitHub or GitLab repository, or an existing image. Creates or updates a standard workload with production defaults (health checks, and two replicas so a deploy never takes it offline), grants…
- **Add database** (Add). Install PostgreSQL, MySQL, MariaDB, MongoDB, or Redis from the Template Catalog with credentials Control Plane generates, let the named workloads connect, and return the host, port, and the env values an app uses as `cpln://secret` references. No credential passes through the…
- **Diagnose workload** (Action). Find out why a workload is unhealthy: reads its deployments, events, and recent error logs, and returns each likely cause with its evidence and the fix. Also in `readonly`.
- **Restart workload** (Restart). Replace every replica with a fresh one on the same spec, so the workload rereads its secrets and env, then wait until it is ready.
- **Rollback workload** (Action). Put a workload back on its previous image, or on a given one, changing nothing else, then wait until it is ready.
- **Promote workload** (Action). Run a workload in another GVC of the same org with its current spec, such as staging to production, with an optional image and env values for the target. Grants access to the secrets its env references and overwrites a workload of the same name there.
- **Allow workload access** (Action). Let other workloads reach a workload through its internal firewall, keeping every other rule, and return the internal URL the callers use. Also takes callers back out.
- **Grant cloud access** (Action). Give a workload credential-free access to AWS, GCP, or Azure through an existing cloud account: sets up its identity, binds the access, and waits until the identity reports it usable.
- **Create gvc** (Create). Create a GVC with one or more cloud locations. If you leave the location to the assistant, it picks one and tells you which.
- **Update gvc** (Update). Update a GVC's settings, such as its description, tags, or pull secrets.
- **Add gvc locations** (Add). Add one or more cloud locations to an existing GVC.
- **Remove gvc locations** (Delete). Remove cloud locations from a GVC.
- **Create workload** (Create). Create a serverless, standard, stateful, or cron workload with its containers and exposure.
- **Update workload** (Update). Update an existing workload — image, resources, scaling, environment, and more.
- **Grant workload secret access** (Action). Grant an existing workload access to a secret by wiring its identity and access policy. Never returns secret values.
- **Workload start cron** (Start). Trigger an immediate run of a cron workload.
- **Workload stop replica** (Stop). Terminate one running replica of a workload; the platform reschedules a replacement per the scaling settings.
- **Configure workload load balancer** (Action). Set or clear the direct per-location load balancer, geo headers, and replica-direct routing.
- **Configure workload security** (Action). Set or clear the pod-level security context (filesystem group, run-as user).
- **Configure workload rollout** (Action). Set or clear how updates roll out — surge, unavailability, and scaling policy.
- **Configure workload retry** (Action). Set or clear the retry behavior for failed requests.
- **Configure workload sidecar** (Action). Set or clear the Envoy proxy filter chain. Advanced.
- **Configure workload local options** (Action). Set or clear per-location overrides of the default options.
- **Configure workload extras** (Action). Set or clear BYOK-only Kubernetes customizations (affinity, tolerations, spread constraints).
- **Write app files** (Action). Write or edit an app's files (whole text files, appends for a large file in parts, exact-text edits, deletions, and moves or renames, uploaded files included) under an app name, for chats that cannot write files or agents without the `cpln` CLI (an agent with a filesystem and…
- **Build image** (Action). Build an image from a GitHub or GitLab repository, or from the app files stored with `write_app_files`, and push it to the org's private registry. Returns a build id; the build keeps running after the call returns. Building an existing `NAME:TAG` replaces that image.
- **Get image build** (Get). Read a build's status, progress events, and log by its build id.
- **Create app files upload link** (Create). Get an upload link for files you have to provide (pictures, fonts, PDFs, data). Open it in a browser and drop every file at once: the page sorts each one into place, such as the logo into its own spot and a set of photos into their folder, where order does not matter, and you…
- **Get app files** (Get). List an app's stored files, read one (in slices for a large file), or get a short-lived download link (tar.gz) for all of them. Also reports where each of the app's images was built from: stored files, a repository, a folder uploaded with the CLI, or a push outside a Control…
- **Create secret** (Create). Create a secret with random values Control Plane generates now, or get a Console link prefilled with its name, type, and keys where you type the values. No input accepts a value and no result contains one.
- **Rotate secret** (Rotate). Replace a secret's values, generated again or entered by you through a Console link, and restart the workloads that use it. Anything outside Control Plane that holds the old values stops working.
- **Create domain** (Create). Put a domain in front of a workload: from the domain, workload, and GVC it derives the 443 listener, the route, and `cname` mode, and returns the DNS records to add. A custom setup (other listeners, `ns` mode, several routes) passes the ports and DNS mode instead.
- **Update domain** (Update). Update a domain's metadata, host/subdomain acceptance flags, and GVC or workload binding.
- **Add domain port** (Add). Add a port listener (for example, 443/http2) to a domain.
- **Remove domain port** (Delete). Remove a port listener from a domain.
- **Add domain route** (Add). Add a route mapping a path or prefix to a workload.
- **Update domain route** (Update). Update an existing route on a domain listener.
- **Remove domain route** (Delete). Remove a route from a domain listener.
- **Set domain tls** (Set). Set the TLS configuration on a domain listener.
- **Clear domain tls** (Clear). Clear the TLS configuration from a domain listener.
- ...and 69 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
