# Iru (formerly Kandji) MCP connector

The Iru (formerly Kandji) connector brings your Apple device fleet, installed apps, library items, blueprints and users into Claude, ChatGPT, Cursor and any MCP client, so your team can ask about and update devices while every call stays inside their own Iru access.

Source: https://elaichi.ai/connectors/kandji/

## Facts

| | |
| --- | --- |
| Application | Iru (formerly Kandji) |
| Category | Device Management |
| AI tools | 11 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | Yes |

## What you can ask once Iru (formerly Kandji) is connected

- List all Iru devices missing their assigned blueprint.
- Which Iru devices have apps out of date?
- Show Iru users with more than two devices.

## Connect Iru (formerly Kandji) in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Iru (formerly Kandji).
2. Optionally set Share with, then press Connect.
3. Paste an Iru (formerly Kandji) API key. One person generates a token in Iru (formerly Kandji) and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Iru (formerly Kandji) tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Iru (formerly Kandji) to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Iru (formerly Kandji) to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Iru (formerly Kandji) to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Iru (formerly Kandji) to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Iru (formerly Kandji) tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Iru (formerly Kandji) through Elaichi

### Find out who has which Mac

IT. Ask which devices are enrolled in Iru (formerly Kandji), who each one is assigned to, and when it last checked in, without opening the console or exporting a spreadsheet.

### Check installed apps before replying to a ticket

Help desk. Pull up a colleague's device in Iru (formerly Kandji), see which apps are installed and which library items have reached it, and answer the ticket with facts instead of a guess.

### Confirm required software reached every device

Security. Compare the apps and library items on each Iru (formerly Kandji) device against what should be there, and get a list of the machines that are missing something.

### Understand what a blueprint actually sets

IT. Look at the blueprints in Iru (formerly Kandji), read what a specific one configures, and see which devices sit under it before changing a policy.

### Clean up when someone leaves

People. Look up the departing person's user record and devices in Iru (formerly Kandji), update the device details, and remove the user record once hardware is returned.

### Keep the hardware inventory current

Operations. Update asset tags and assigned users on Iru (formerly Kandji) devices as laptops move between people and offices, so the device list matches what is on desks.

## Frequently asked questions

### How do I connect Iru (formerly Kandji) to Claude?

Connect Iru (formerly Kandji) in Elaichi first, which asks you to paste an API key from your Iru settings. There is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude will ask you to sign in to Elaichi as yourself, and your Iru devices, users and blueprints are available from then on.

### Does Iru (formerly Kandji) work with ChatGPT and Cursor as well as Claude?

Yes. Once Iru (formerly Kandji) is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Iru once and every client you use picks it up.

### What can an AI agent actually do with my Iru (formerly Kandji) data?

An agent connected to Iru (formerly Kandji) can list your enrolled devices, open a single device and report who it is assigned to and when it last checked in, and show which apps and library items are on it. It can read your blueprints, look up users, update device details such as asset tag or assigned user, and remove a device or user record when you ask it to. It cannot do anything in Iru that you could not do yourself.

### Does connecting Iru (formerly Kandji) give the AI access to my whole device fleet?

No. Every call to Iru (formerly Kandji) runs inside the access of the person who signed in, so the AI sees the devices, users and blueprints that person's Iru permissions allow and nothing more. Elaichi can narrow that further by hiding actions like deleting devices, but it can never grant more than the person already has in Iru.

### Can my team share one Iru (formerly Kandji) connection?

Yes. One administrator connects Iru (formerly Kandji) with the API key and shares the connection with a team in Elaichi, and nobody else ever sees or handles that key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person who looked up a device or updated a user, not a shared account.

### Can I stop an agent from deleting or changing things in Iru (formerly Kandji)?

Yes. Restrictions in Elaichi apply per action, so you can allow reading Iru (formerly Kandji) devices, apps and blueprints while blocking updates and deletions of devices or users. A blocked action is never advertised to Claude, ChatGPT or any other client, so no prompt, however worded, can reach it.

### What happens to an Iru (formerly Kandji) connection when someone leaves?

When you offboard a person in Elaichi, their access to Iru (formerly Kandji) through every AI client ends at once. If they had shared an Iru connection with a team, it keeps working for everyone else. If you want Iru gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

## All 11 Iru (formerly Kandji) tools

Every tool below is callable through https://api.elaichi.ai/mcp once Iru (formerly Kandji) is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Iru (formerly Kandji) devices** (List). Get a list of devices in Kandji. Returns fields including device_id, device_name, model, platform, os_version, serial_number, user, and tags.
- **Get single Iru (formerly Kandji) device by ID** (Get). Get device details for a specified device in Kandji. Requires device id. Returns device information including hardware, software, and status fields.
- **Update a Iru (formerly Kandji) device by ID** (Update). Update device information in Kandji using id. Supports updating user assignment, asset_tag, blueprint_id, and tags. Use null to clear asset_tag or user, and empty list to clear tags. Returns updated device fields.
- **Delete a Iru (formerly Kandji) device by ID** (Delete). Delete a specific device in Kandji using id. This removes the device record, unenrolls it from MDM, and automatically uninstalls the agent on next check-in for macOS and Windows devices. Returns no content.
- **List all Iru (formerly Kandji) device apps** (List). Get a list of all installed apps for a specified device in Kandji. Requires device_id. The response includes app details, such as name and version.
- **List all Iru (formerly Kandji) device library items** (List). Get all library items and their statuses for a specified device in Kandji. Returns fields including library item status indicating availability, installation state, and compatibility.
- **List all Iru (formerly Kandji) blueprints** (List). Get a list of blueprints in Kandji. Returns blueprint records with details such as id and name.
- **Get single Iru (formerly Kandji) blueprint by ID** (Get). Get information about a specific blueprint in Kandji using id. Returns blueprint details including configuration and metadata.
- **List all Iru (formerly Kandji) users** (List). List users in Kandji. Returns an array of users with key details such as id, email, name, active, archived, created_at, updated_at, department, job_title, device_count, and integration information.
- **Get single Iru (formerly Kandji) user by ID** (Get). Get details for a specific user in Kandji using id. Returns key fields including name, email, active status, department, job_title, device_count, and integration details such as id, name, and type.
- **Delete a Iru (formerly Kandji) user by ID** (Delete). Delete a specific user in Kandji by id. Returns no content on success. If the user is still assigned to one or more devices, a 400 error with 'detail' explaining the assignment issue is returned.
