Skip to content

Device Management

Jamf MCP connector

The Jamf connector brings your Macs, iPhones, iPads, users and admin accounts into Claude, ChatGPT, Cursor and any MCP client, so your team can look up, enroll and update managed devices in plain language.

  • How it connects. App credentials. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Jamf to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Jamf once

  1. Open Connections, choose Add connection, and pick Jamf.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste your Jamf app credentials. Jamf authenticates the app rather than a person. One person supplies the credentials once, and everyone else works through Share with.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

jamf
Jamf
Ayla Networks
Iru (formerly Kandji)
ManageEngine MDM
Microsoft Intune
N-able N-central
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect Jamf to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect Jamf to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect Jamf to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Jamf to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Jamf through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • IT

    Find every Mac that has gone quiet

    Ask which computers in Jamf inventory have not checked in recently, then update the record once the machine is found or written off.

  • Support

    Look up a device while the ticket is open

    Pull the serial number, assigned user and installed apps for a colleague's iPhone or MacBook from Jamf without leaving the conversation.

  • Security

    Spot phones still carrying an old app

    List the mobile device applications in Jamf, find the versions that should be gone, and update or remove the entries that no longer belong.

  • People

    Set up a new hire on day one

    Create the person's Jamf user record, assign their laptop and phone, and confirm everything shows up before they walk in.

  • Operations

    Reconcile the hardware list before a refresh

    Compare what Jamf computer inventory says you own against what is on desks, then correct locations, models and owners in one pass.

  • IT

    Review who holds a Jamf admin account

    List every Jamf account, check who still needs elevated access, and remove or update the ones that should have gone months ago.

Try asking

  • “List all Jamf mobile devices enrolled this month.”
  • “Which Jamf users have no assigned mobile device?”
  • “Show Jamf accounts with administrator privileges.”

See all 25 Jamf tools below

AI tools

Jamf tools for your AI agents

25 tools are ready to call through Elaichi's MCP endpoint the moment you connect Jamf, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Jamf gets you

6 screens from the product, each doing one job for your Jamf account.

The agent

Ask about Jamf devices in plain language.

Starter prompts return live mobile devices, users and accounts from Jamf.

  • accounts
  • users
  • mobile devices
  • privileges

Ask Elaichi to work across your apps.

List all Jamf mobile devices enrolled this month.

Which Jamf users have no assigned mobile device?

Show Jamf accounts with administrator privileges.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Jamf.

One governed MCP endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

25 Jamf tools ready without custom code.

Browse Jamf accounts, users and mobile device methods in one catalog.

  • List all Jamf accounts
  • Get single Jamf account by ID
  • Delete a Jamf account by ID
  • Update a Jamf account by ID
ElaichiTools
Tool Action Description
List all Jamf accounts List List all account users or admin users in Jamf. Returns an array of account objects containing id and name fields for each account.
Get single Jamf account by ID Get Get details of a specific account user or admin user in Jamf by id. Returns id, name, email, enabled status, access_level, privilege_set, site, and privileges related to JSS objects, settings, actions, and tools.
Delete a Jamf account by ID Delete Delete a specific account user or admin user in Jamf using its id. Returns a 200 OK response when the account is successfully deleted.
Update a Jamf account by ID Update Update an existing account user or admin user in Jamf using the specified id. Returns updated fields including name, email_address, access_level, privilege_set, and enabled status.
Create a Jamf account Create Create a new account in Jamf using id. Requires id. Returns details such as name, email, full_name, access_level, and privilege_set in the response.

Toolboxes

Every team gets its own Jamf toolbox.

Toolboxes scope IT, security and helpdesk to the Jamf tools they need.

  • IT operations
  • Security
  • Helpdesk
  • Onboarding
ElaichiToolboxes
Name Source template Tools Created

IT operations toolbox

Jamf · mobile devices and enrolment

Jamf starter 18 Mar 4, 2026

Security toolbox

Jamf · accounts and privileges

9 Mar 2, 2026

Helpdesk toolbox

Jamf · users and device lookups

24 Feb 27, 2026

Onboarding toolbox

Jamf · new users and device assignment

Jamf starter 6 Feb 19, 2026

Asset management toolbox

Jamf · device inventory and records

31 Jan 30, 2026

Compliance toolbox

Jamf · account reviews and audit trails

12 Jan 22, 2026

Shared connections

Teammates use Jamf without seeing credentials.

The connections table shows who connected each Jamf account and its sharing.

  • IT EMEA
  • Security
  • Helpdesk
  • Onboarding
ElaichiConnections
Connection Scope Status Access
JA

Jamf (IT EMEA)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
JA

Jamf (Security)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
JA

Jamf (Helpdesk)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
JA

Jamf (Onboarding)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
JA

Jamf (Field devices)

Connected by Clara Nowak

Personal • Active Not shared
JA

Jamf (Compliance)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Answer who touched which Jamf device.

Append-only entries record when, who, what happened, type and resource.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Jamf Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Jamf Accounts Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Jamf Accounts List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule drafts your Jamf device digest.

Six steps fetch mobile devices, group them, draft, await approval, post to Jamf.

Jamf digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch accounts

    Jamf

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Jamf

    Queued

Collections and dashboards

Jamf enrolment numbers land before anyone asks.

Four metrics, 14 days of new devices and a team breakdown, refreshed on schedule.

Jamf health

Refreshed 4 minutes ago · every 15 minutes · from the accounts collection

Live

Accounts

1,284 ↓ 12%

Users

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Accounts created

Last 14 days

By team

Share of activity

IT EMEA 34%

Security 27%

Helpdesk 21%

Onboarding 18%

FAQ

Frequently asked questions

How do I connect Jamf to Claude?

Open Elaichi, choose Jamf from the connector catalog, and sign in with your Jamf app credentials. There is no OAuth application to register and no client ID or secret to generate. Then in Claude go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Claude will ask you to sign in to Elaichi as yourself, and your Jamf devices, users and accounts are available from then on.

Does Jamf work with ChatGPT and Cursor as well as Claude?

Yes. Once Jamf is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Jamf once and every client you use picks it up.

What can an AI agent actually do with my Jamf data?

With Jamf connected, an agent can list and search your managed Macs, iPhones and iPads, look up a single device by its ID, and update inventory details like owner or location. It can also create and update Jamf users, review which apps are deployed to mobile devices, and manage the admin accounts that sign in to Jamf itself. In practice that means asking questions like which devices a person has, or which machines have not reported in, and getting an answer from live Jamf records.

Does connecting Jamf give the AI access to every device in my Jamf instance?

No. Every call to Jamf runs inside the access of the person who signed in, so an agent can only see and change the devices, users and accounts that person could already reach in Jamf. Elaichi can narrow that further, for example to read-only or to a subset of actions, but it can never widen it beyond what Jamf itself allows that person.

Can my team share one Jamf connection?

Yes. One administrator connects Jamf in Elaichi and shares the connection with a team, and nobody else ever handles the Jamf app credentials. Each teammate still signs in to Elaichi as themselves, so when someone updates a device record or removes a user, the audit log names that person rather than the shared connection.

Can I stop an agent from deleting or changing things in Jamf?

Yes. Restrictions in Elaichi work per action, so you can allow looking up devices and users in Jamf while blocking deletes or edits entirely. A blocked action is never shown to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.

What happens to a Jamf connection when someone leaves?

Offboarding a person in Elaichi ends their access to Jamf through every client at once, with no separate step in Claude, ChatGPT or Cursor. If they were using a shared Jamf connection, it keeps working for everyone else on the team. If you ever want Jamf gone completely, disconnecting it once in Elaichi removes it from every client at the same time.

Put Jamf in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.