# Kong Konnect MCP connector

The Kong Konnect connector lets Claude, ChatGPT, Cursor, and the Elaichi Agent search your gateway services, routes, and consumers, look up how each one works, and make approved changes, with every call signed in as you and logged.

Source: https://elaichi.ai/connectors/kong-konnect/

## Facts

| | |
| --- | --- |
| Application | Kong Konnect |
| Category | Application Development |
| AI tools | 3 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Kong Konnect builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support.konghq.com/support/s |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Kong Konnect is connected

- Which routes point at the payments service in production?
- List consumers on the partner control plane without a rate limit plugin.
- Add a consumer for Acme and attach the key auth plugin.

## Connect Kong Konnect in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Kong Konnect.
2. Optionally set Share with, then press Connect.
3. Approve it in Kong Konnect. Kong Konnect's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Kong Konnect tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Kong Konnect MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Kong Konnect MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Kong Konnect MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Kong Konnect to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Kong Konnect tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Kong Konnect through Elaichi

### Find which route fronts a service

Platform. Ask which gateway routes point at a service and which consumers call it, then make the change while the conversation is still open.

### Check who holds a consumer credential

Security. List the consumers on a control plane, see which plugins guard them, and tighten a rate limit or auth plugin from the chat.

### Keep the API catalog current

API product. Look up an API product in Kong Konnect, check what is published to the developer portal, and update the description without opening the console.

### Answer a partner's access question

Support. When a partner says their key stopped working, find their consumer, see the plugins on their route, and fix what is blocking them.

### Roll out a plugin change across routes

Operations. Ask what fields a rate limiting plugin accepts, then apply the same setting to every route that needs it.

### Onboard a new team to the gateway

Developer relations. Register their service and routes, add a consumer, and hand back a plain summary of everything that was created.

## Elaichi vs Zapier MCP vs Composio for Kong Konnect

All three can connect Kong Konnect to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Kong Konnect tools | Allow or restrict single Kong Konnect tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Kong Konnect call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Kong Konnect to Claude?

Open Elaichi, pick Kong Konnect from the catalog, and sign in to Kong Konnect over OAuth; there is no OAuth application to register and no client ID or secret to generate. Then in Claude go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Sign in to Elaichi when Claude asks, and Kong Konnect is ready to use.

### Does Kong Konnect work with ChatGPT and Cursor as well as Claude?

Yes. Kong Konnect is connected once in Elaichi, and the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. Connect it once and every client you use sees it.

### What can an AI agent actually do with my Kong Konnect data?

It can search across your Kong Konnect control planes for services, routes, consumers, and plugins, look up what fields each one takes, and make a change you ask for, such as adding a consumer or adjusting a rate limit. Short, concrete asks work better than long sentences: "show me the routes on the payments service" gets a cleaner answer than a paragraph.

### Does connecting Kong Konnect give the AI every control plane?

No. The AI works inside the Kong Konnect access of whoever signed in, so it only sees the control planes, services, and consumers that person can already open. Elaichi can narrow that further, for example to searching and reading only, but it can never widen it beyond what Kong Konnect granted.

### Can my team share one Kong Konnect connection?

Yes. One person connects Kong Konnect and shares it with a team in Elaichi, and nobody else ever handles a token. Each teammate still signs in to Elaichi as themselves, so the audit log names the person behind each change to a service or plugin.

### Can I stop an agent from deleting or changing things in Kong Konnect?

Yes. Restrictions in Elaichi are set per action, so you can allow searching and looking up Kong Konnect services while blocking anything that creates, edits, or deletes. A restricted action is never advertised to Claude or any other client, so no prompt, however worded, can reach it.

### What happens to a Kong Konnect connection when someone leaves?

Offboarding the person in Elaichi ends their access to Kong Konnect through every client at once. A connection they shared keeps working for everyone else on the team. Disconnecting Kong Konnect once in Elaichi removes it from Claude, ChatGPT, Cursor, and the Elaichi Agent together.

### Does the Kong Konnect MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Kong Konnect is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Kong Konnect?

Yes. Both let Claude, ChatGPT or Cursor use Kong Konnect. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Kong Konnect call.

### How is Elaichi different from Composio for Kong Konnect?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Kong Konnect: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 3 Kong Konnect tools

Every tool below is callable through https://api.elaichi.ai/mcp once Kong Konnect is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Search** (Search). Finds relevant API operations based on a description of what you want to do (e.g. "list all services in a control plane").
- **Get schema** (Get). Retrieves the full/partial (as required) schema for a specific operation, so the AI knows exactly what parameters and request body fields are required.
- **Execute** (Execute). Calls the API operation with the appropriate inputs, based on what get_schema returned.
