Skip to content

Compliance

Lumos MCP connector

The Lumos connector brings your apps, users, accounts, groups, roles, and activity logs into Claude, ChatGPT, Cursor, and the Elaichi Agent, so anyone on your team can ask who has access to what and get an answer from Lumos itself.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Lumos to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Lumos once

  1. Open Connections, choose Add connection, and pick Lumos.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste a Lumos API key. One person generates a token in Lumos and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

lumos
Lumos
Alloy
Cakewalk
Comp AI
ComplyCube
Drata
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect Lumos to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect Lumos to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect Lumos to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Lumos to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Lumos through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • IT

    Answer who has access to what

    Ask which accounts a person holds across every app in Lumos, or which people hold accounts in one app, without opening a single admin console.

  • Security

    Trace identity events after an alert

    Pull the identity events and activity logs around a suspicious sign-in, then ask for the sequence in plain language so the picture is clear before anyone escalates.

  • Compliance

    Gather evidence for an access review

    List every account and role in a system that is in scope for an audit, group the results by team, and hand the reviewer a ready list instead of a spreadsheet exercise.

  • IT

    Add a new app to the Lumos catalog

    When the business adopts a tool, create the app in Lumos, put it in the right category, and adjust its settings from the same conversation.

  • People Ops

    Confirm a leaver's accounts are closed

    On someone's last day, check every account still attached to them in Lumos and flag anything that has not been removed yet.

  • Procurement

    See which apps are really in use

    Before a renewal, pull the app, its category, and how many accounts exist in it, so the conversation with the vendor starts from real numbers.

Try asking

  • “List Lumos apps added in the last 30 days.”
  • “Which Lumos users have accounts in the finance apps?”
  • “Summarize app settings changed across Lumos this week.”

See all 88 Lumos tools below

AI tools

Lumos tools for your AI agents

88 tools are ready to call through Elaichi's MCP endpoint the moment you connect Lumos, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Lumos gets you

6 screens from the product, each doing one job for your Lumos account.

The agent

Ask about Lumos apps, get real answers.

Question Lumos apps, users and accounts in plain language, answered from live records.

  • apps
  • app settings
  • users
  • user accounts

Ask Elaichi to work across your apps.

List Lumos apps added in the last 30 days.

Which Lumos users have accounts in the finance apps?

Summarize app settings changed across Lumos this week.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Claude, ChatGPT and Cursor reach Lumos here.

One org-wide MCP endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

88 Lumos tools ready to call.

Apps, app settings, users, user accounts and webhooks, with no custom code.

  • List all Lumos apps
  • Create a Lumos app
  • Get single Lumos app by ID
  • Update a Lumos app by ID
ElaichiTools
Tool Action Description
List all Lumos apps List List all apps in your Lumos company catalog. Returns a collection of app records each including id, name, and optionally custom_attributes when expanded. Supports filtering by name_search and exact_match.
Create a Lumos app Create Create a new app in Lumos. Returns the created app object including id and name.
Get single Lumos app by ID Get Get a single Lumos app by id. Returns the app object including id, name, and optionally custom_attributes when the expand parameter is provided. Required: id.
Update a Lumos app by ID Update Update domain-specific metadata overrides for a Lumos app instance. This updates the app in your domain, not the shared Lumos app catalog. Returns the updated app object including id and name. Required: id.
List all Lumos apps categories List List all app categories available in Lumos. Returns an array of category name strings. No required parameters.

Toolboxes

Every team gets its own Lumos toolbox.

Curate one toolbox per team so IT and Compliance see different Lumos tools.

  • IT
  • Compliance
  • Security
  • People Ops
ElaichiToolboxes
Name Source template Tools Created

IT toolbox

Lumos · apps and app settings

Lumos starter 18 Mar 4, 2026

Compliance toolbox

Lumos · access reviews and evidence

9 Mar 2, 2026

Security toolbox

Lumos · user accounts and webhooks

24 Feb 27, 2026

People Ops toolbox

Lumos · joiners and leavers

Lumos starter 6 Feb 19, 2026

Procurement toolbox

Lumos · app categories and owners

31 Jan 30, 2026

Support toolbox

Lumos · user and account lookups

12 Jan 22, 2026

Shared connections

Teammates use Lumos without holding credentials.

See who connected each Lumos account and how many teams and members share it.

  • IT Core
  • Compliance
  • Security Ops
  • People Ops
ElaichiConnections
Connection Scope Status Access
LU

Lumos (IT Core)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
LU

Lumos (Compliance)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
LU

Lumos (Security Ops)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
LU

Lumos (People Ops)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
LU

Lumos (Procurement)

Connected by Clara Nowak

Personal • Active Not shared
LU

Lumos (Support)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Every Lumos call is on the record.

When, who, what happened, type and resource, appended for each Lumos request.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Lumos Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Lumos Apps Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Lumos Apps List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule runs the whole Lumos review.

Fetch Lumos apps, group them, draft a digest, approve, then post back.

Lumos digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch apps

    Lumos

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Lumos

    Queued

Collections and dashboards

Lumos health arrives before anyone asks.

Four metrics, 14 days of records created and a team breakdown, computed on schedule.

Lumos health

Refreshed 4 minutes ago · every 15 minutes · from the apps collection

Live

Apps

1,284 ↓ 12%

App settings

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Apps created

Last 14 days

By team

Share of activity

IT Core 34%

Compliance 27%

Security Ops 21%

People Ops 18%

FAQ

Frequently asked questions

How do I connect Lumos to Claude?

First connect Lumos in Elaichi, which asks for a Lumos API key and nothing else, so there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Claude will ask you to sign in to Elaichi, and from then on your Lumos apps, users, and accounts are available in the conversation.

Does Lumos work with ChatGPT and Cursor as well as Claude?

Yes. Once Lumos is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Lumos once and every client sees it.

What can an AI agent actually do with my Lumos data?

With Lumos connected, an agent can look up a person and list the accounts, groups, and roles they hold, list the apps in your catalog and their categories, and read identity events and activity logs to explain what happened and when. It can also create and update apps and their settings, and upload account lists for systems Lumos does not reach on its own. Because Lumos exposes a lot of capabilities, short concrete asks such as "list Jane's accounts" work better than long paragraphs.

Does connecting Lumos give the AI access to everything in my Lumos workspace?

No. Every call into Lumos runs as the person who signed in, so the agent sees only the apps, users, and accounts that person's Lumos permissions already allow. Elaichi can narrow that further with restrictions, but it can never widen it beyond what Lumos itself grants.

Can my team share one Lumos connection?

Yes. One administrator connects Lumos in Elaichi and shares the connection with a team, and nobody else ever sees or handles the API key. Each teammate still signs in to Elaichi as themselves, so every action against Lumos is recorded under their own name in the audit log.

Can I stop an agent from changing things in Lumos?

Yes. Restrictions in Elaichi are set per action, so you can allow reading users, accounts, and activity logs from Lumos while blocking the ability to create or update apps and settings. A blocked action is never shown to Claude, ChatGPT, Cursor, or any other client, so no prompt, however worded, can reach it.

What happens to a Lumos connection when someone leaves?

Offboarding that person in Elaichi ends their access to Lumos through every AI client at once. If they were using a shared Lumos connection, it keeps working for everyone else on the team. If you want the connection gone entirely, disconnecting Lumos once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.

Put Lumos in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.