# Orca Security MCP connector

The Orca Security connector brings your cloud alerts, assets, vulnerabilities, cloud accounts and scans to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person can ask about and act on Orca Security findings inside their own access.

Source: https://elaichi.ai/connectors/orcasecurity/

## Facts

| | |
| --- | --- |
| Application | Orca Security |
| Category | Security |
| AI tools | 40 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. 40 tools is past the 30-tool threshold, so clients use `search_tools` and `execute_tool` |

## What you can ask once Orca Security is connected

- Show high severity Orca Security alerts opened this week.
- Which cloud accounts have the most open vulnerabilities?
- List remediation actions for critical alerts on production assets.

## Connect Orca Security in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Orca Security.
2. Optionally set Share with, then press Connect.
3. Paste an Orca Security API key. One person generates a token in Orca Security and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Orca Security tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Orca Security to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Orca Security to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Orca Security to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Orca Security to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Orca Security tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Orca Security through Elaichi

### Triage this morning's alerts

Security operations. Ask for the open Orca Security alerts on production accounts, sorted by severity, and get the event log and recommended remediation for the ones that matter.

### Find what a vulnerability actually touches

Cloud engineering. Ask which assets carry a given CVE and which cloud accounts they sit in, then read the remediation steps before opening a change.

### Pull the full story behind one alert

Incident response. Get a single Orca Security alert with its event history, malware findings and linked Jira ticket in one place while the call is still going.

### Check coverage across cloud accounts

Compliance. List every connected AWS and GCP account in Orca Security, see which are scanned, and spot the ones with outstanding remediation before an audit.

### Kick off a scan after a deploy

Platform engineering. Start an Orca Security scan on a new environment or a vendor's asset and check the result later without leaving the tool you are working in.

### Summarize risk for the weekly review

Security leadership. Ask for a plain-language rundown of alert counts by severity and account, with the assets driving the most findings, ready to paste into a report.

## Frequently asked questions

### How do I connect Orca Security to Claude?

Two steps. In Elaichi, choose Orca Security and paste in your Orca Security API key, which is the only sign-in step, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and Orca Security is ready to use.

### Does Orca Security work with ChatGPT and Cursor as well as Claude?

Yes. Once Orca Security is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Orca Security once and every client picks it up.

### What can an AI agent actually do with my Orca Security data?

An agent can list and read Orca Security alerts, pull an alert's event log, vulnerabilities, malware findings, remediation actions and linked Jira ticket, browse your assets and cloud accounts, and start or check a scan. It cannot do anything the connector does not cover, and it cannot do anything the signed-in person could not do in Orca Security. Because Orca Security has many actions, short concrete asks such as "critical alerts on the payments account" get better results than long paragraphs.

### Does connecting Orca Security give the AI every cloud account and alert?

No. Access follows the person who signed in, so the agent sees the Orca Security cloud accounts, assets and alerts that person's own Orca Security account can see, and nothing beyond it. Elaichi can narrow that further, for example to read-only or to a subset of actions, but it can never widen access past what Orca Security already grants.

### Can my team share one Orca Security connection?

Yes. One person connects Orca Security in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so every Orca Security call in the audit log names the person who made it, not the person who connected it.

### Can I stop an agent from changing or deleting things in Orca Security?

Yes. Restrictions in Elaichi work per action, so you can allow reading Orca Security alerts and assets while blocking starting scans or changing alert state. A blocked action is never advertised to Claude, ChatGPT, Cursor or any other client, so no prompt, however worded, can reach it.

### What happens to an Orca Security connection when someone leaves?

Offboarding a person in Elaichi ends their access to Orca Security through every client at once, with no need to touch Orca Security itself. If they were using a shared Orca Security connection, it keeps working for everyone else on the team. Disconnecting Orca Security once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

## All 40 Orca Security tools

Every tool below is callable through https://api.elaichi.ai/mcp once Orca Security is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Orca Security alerts** (List). Retrieve alerts from Orca Security. The response provides detailed information about the retrieved alerts, including their attributes and related data.
- **Get single Orca Security alert by ID** (Get). Retrieves details of a specific alert identified by its id from Orca Security. The response contains information related to the alert, including remediation details, compliance status, asset details, and more.
- **Orca Security alerts event logs** (Action). Use this endpoint to retrieve the event log for a specific alert by providing the alert_id. The response includes a list of events related to that alert, along with metadata for each event.
- **Orca Security alerts state** (Action). Use this endpoint to retrieve the current state of a specific alert identified by its alert_id. The response includes detailed information such as the alert's severity, rule source, timestamps for creation and last update, verification status, risk level, Orca score, current status, and more.
- **List all Orca Security alerts scheme** (List). Retrieves a list of alerts and their details from Orca Security. The response includes an array of "alerts" with attributes such as type, rule information, compliance status, asset details, severity, cloud provider information, connectivity details, vulnerabilities, etc.
- **List all Orca Security alerts vulns** (List). Fetches a list of vulnerability alerts from Orca Security. Each alert includes details like CVE findings, severity, affected assets, fix availability, and related cloud account and organization data.
- **List all Orca Security alerts remediation actions** (List). Use the endpoint to get remediation action and template IDs relevant to a specific alert type, such as "vulnerability". This helps identify which remediation steps can be applied to alerts of that type, enabling automated or guided response actions.
- **List all Orca Security alerts vulns malware** (List). Use the endpoint to retrieve alerts from Orca Security for specified types such as vulnerability, malware, or both. The response includes detailed alert information, such as CVE details, severity levels, fix availability, affected packages, CVSS scores, exploit data, and more.
- **List all Orca Security assets** (List). Use the endpoint to retrieve a list of assets from the Orca Security platform. The response includes asset details such as name, type, scan status, associated cloud account, model, state, and Orca tags.
- **Orca Security assets scheme** (Action). Use the endpoint to retrieve the schema definition of assets from the Orca Security platform. The response includes metadata about asset structure, such as asset type, category, cloud provider, organization, connectivity, access, tags, risk level, configuration, and state.
- **Create a Orca Security session** (Create). Use this endpoint to create a new user session by providing a valid security_token. This initiates authentication and returns session details upon success.
- **Delete a Orca Security session by ID** (Delete). Use this endpoint to terminate the current user session, effectively logging the user out and revoking the session token.
- **List all Orca Security cloud accounts** (List). Use the endpoint to retrieve a list of connected cloud accounts from the Orca Security platform, including detailed metadata and aggregated statistics. The response includes information such as cloud provider type (e.g., AWS, GCP), account status, onboarding status, scan limitations, tags, remediation configurations, and DSPM (Data Security Posture Management) setup.
- **Get single Orca Security cloud account by ID** (Get). Use this endpoint to retrieve detailed information about a specific cloud account in Orca Security by its unique ID. The response includes metadata such as cloud provider, account status, permissions, scan configuration, tags, and other relevant account-level settings.
- **List all Orca Security accounts remediation** (List). Use this endpoint to retrieve remediation configuration details for a specific cloud account, including the template and remediation_action values. These values are needed when configuring or triggering automated remediation workflows in Orca Security.
- **List all Orca Security cloudtrail discovery** (List). Use this endpoint to discover AWS CloudTrail configurations across connected AWS accounts in Orca Security. It helps identify available CloudTrail trails and assess their readiness for onboarding and security monitoring.
- **List all Orca Security gcp accounts** (List). Use this endpoint to retrieve a list of GCP accounts available for mass onboarding in Orca Security. It provides information needed to initiate and manage the onboarding of multiple Google Cloud projects or accounts.
- **Get single Orca Security alert jira info by ID** (Get). Use this endpoint to retrieve Jira integration details for a specific alert in Orca Security. It returns information such as the linked Jira ticket, status, and any synchronization details between Orca and Jira for the given alert ID.
- **Get single Orca Security scan by ID** (Get). Use this endpoint to retrieve the current status of a specific scan in Orca Security by providing its unique scan ID. The response includes information about the scan’s progress, completion state, and any issues encountered during execution.
- **Create a Orca Security scan** (Create). Use this endpoint to create and launch a new security scan for a specific asset in Orca Security.
- **Create a Orca Security vendor scan asset** (Create). Use this endpoint to create and launch a scan for a specific asset using its cloud provider ID, asset type, and provider asset ID (such as an AMI or VM ID).
- **List all Orca Security cve scheme** (List). Use this endpoint to retrieve the full schema definition of CVE (Common Vulnerabilities and Exposures) objects in Orca Security. The response outlines all fields available in CVE data, including asset details, severity scores, affected packages, exploit links, and fix status—helpful for understanding, parsing, or validating CVE-related API responses.
- **List all Orca Security sonar schema** (List). Use this endpoint to retrieve the field structure and metadata schema for Sonar findings in Orca Security.
- **List all Orca Security sonar schema models** (List). Use this endpoint to retrieve the schema definition for a specific Sonar model in Orca Security. By specifying the model name (e.g., AzureSqlDbServer) as a query parameter, you can view the fields and structure used for that particular model's findings.
- **List all Orca Security query sonar** (List). Use this endpoint to run custom Sonar queries against cloud resources and identify configurations, such as unrestricted access or misconfigurations.
- **List all Orca Security query schema** (List). Use this endpoint to retrieve the field structure and metadata schema for various data types in Orca Security, including assets, alerts, inventory, logs, and CVEs.
It returns a JSON object with version, status, and data fields describing the schema of each data type.
- **List all Orca Security query catalog** (List). Use this endpoint to retrieve the list of predefined queries available in the Orca Security Query Catalog, along with their associated metadata.
- **List all Orca Security query inventory** (List). Use this endpoint to retrieve filtered inventory data from Orca Security using a DSL-based query. You can apply complex filters using the dsl_filter parameter and optionally request a downloadable result with the get_download_link method.
- **List all Orca Security query alerts** (List). Use this endpoint to retrieve alert data from Orca Security using custom DSL-based filtering. It allows querying specific alert types, severities, statuses, and other attributes to support advanced use cases, such as integrations, dashboards, or automated analysis.
- **Orca Security query alerts show info true** (Search). Use this endpoint to retrieve all alerts, including informational alerts, from the Orca Security API. You can apply a DSL filter to refine the results. The response includes alert details such as asset type, remediation info, compliance status, tags, and more.
- **List all Orca Security query logs** (List). Use this endpoint to retrieve log data from the Orca Security platform. It returns a list of log entries, including status, grouping details, total item counts, and a list of log data objects.
- **List all Orca Security query cves** (List). Use this endpoint to retrieve a list of CVEs (Common Vulnerabilities and Exposures) from the Orca Security platform.
- **List all Orca Security query assets** (List). Use this endpoint to retrieve a list of all assets in your Orca Security environment.

- **List all Orca Security attack paths crown jewels** (List). Use this endpoint to retrieve a list of Crown Jewel assets identified by Orca Security.

- **List all Orca Security chain attack paths** (List). Use this endpoint to retrieve the attack path snapshot for a specific chain.
- **List all Orca Security user audit logs** (List). Use this endpoint to retrieve audit logs related to user activity within Orca Security.
- **Orca Security user audit logs actions** (Action). Use this endpoint to retrieve a list of possible user actions recorded in the audit logs.
- **List all Orca Security auth tokens** (List). Use this endpoint to retrieve a list of active authentication tokens associated with your Orca Security account.
- **Create a Orca Security external service action** (Create). Use this endpoint to initiate a remediation action via an external service in Orca Security. The request must include the service name, remediation template ID, specific remediation action, and a list of alert IDs to which the remediation will be applied.
- **List all Orca Security users** (List). Use this endpoint to list all the users available in Orca Security.
