Skip to content

Socket MCP connector

The Socket connector brings dependency scores, alerts, the threat feed and package file contents into Claude, ChatGPT, Cursor and the Elaichi Agent, where each person sees only what their own Socket account allows.

  • How it connects. Connects over OAuth. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Socket to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Socket once

  1. Open Connections, choose Add connection, and pick Socket.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Approve it in Socket. Socket's own window opens. Whoever approves it decides what this connection can reach.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

socket
Socket
Censys
Herd Security
Infisical
Intruder
Kisi
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Socket MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Socket MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Socket MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Socket to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Socket through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Security

    Triage this morning's alerts before standup

    Ask for the open Socket alerts in your organization, sorted by severity, and get a plain summary of which packages were flagged and why.

  • Engineering

    Check a package before adding it

    Ask for the dependency score of a package and version you are about to install, and hear what pulls the score down before it reaches a pull request.

  • Platform

    Watch the threat feed for your stack

    Ask what has appeared in the Socket threat feed this week that touches the ecosystems you ship, and get the list without opening a dashboard.

  • Incident response

    Look inside a suspicious package

    List the files in a package version, open the install script, and search its contents for a domain or command while the incident is still live.

  • Compliance

    Write up a package risk review

    Pull the score, open alerts and file list for a package into one note that an auditor can read without a Socket login.

  • Open source office

    Compare candidate libraries side by side

    Ask for the dependency scores of three libraries that do the same job and get a short recommendation grounded in Socket's findings.

Try asking

  • “What is the dependency score for lodash 4.17.21?”
  • “Show me open alerts in our organization from this week.”
  • “Search the files in express 4.19 for postinstall scripts.”

See all 7 Socket tools below

Compare

Elaichi vs Zapier MCP vs Composio for Socket

All three can connect Socket to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for Socket, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over Socket tools Allow or restrict single Socket tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per Socket call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

AI tools

Socket tools for your AI agents

7 tools are ready to call through Elaichi's MCP endpoint the moment you connect Socket, governed by the same roles, restrictions, and audit log as everything else in Elaichi. Socket builds and runs these tools.

See it in Elaichi

What connecting Socket gets you

6 screens from the product, each doing one job for your Socket account.

The agent

Ask Socket about a package in plain words.

Dependency scores, open alerts and package files answered from live Socket records.

  • alerts
  • packages
  • organizations
  • package files

Ask Elaichi to work across your apps.

What is the dependency score for lodash 4.17.21?

Show me open alerts in our organization from this week.

Search the files in express 4.19 for postinstall scripts.

Also runs in Claude, ChatGPT or Cursor

MCP clients

Socket in Claude, ChatGPT and Cursor at once.

One governed endpoint over OAuth, no SDK and no shared API key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Tool catalog

7 Socket tools, ready in every client.

Dependency scores, alerts, the threat feed and package files, with no code to write.

  • Depscore
  • Organizations
  • Alerts
  • Threat feed
ElaichiTools
Tool Action Description
Depscore Action Get the dependency score of packages with the `depscore` tool from Socket. Use 'unknown' for version if not known. Use this tool to scan dependencies for their quality and security on existing code or when code is generated. Stop generating code and ask the user how to proceed…
Organizations Action List the Socket organizations the authenticated user belongs to with the `organizations` tool. Use this to discover the `org_slug` values needed by other org-scoped tools (e.g. `alerts`, `threat_feed`), or when the user asks which organizations they have access to.
Alerts Action List the latest security alerts for a Socket organization with the `alerts` tool. Requires `org_slug` — call the `organizations` tool first if you don't have it. Supports filtering by severity, category, status, artifact type/name, alert type, and repo. Use this to surface…
Threat feed Action Look up items in the Socket organization threat feed with the `threat_feed` tool. Requires `org_slug` — call the `organizations` tool first if you don't have it. Returns recently flagged packages (malware, typosquats, obfuscated code, etc.) along with a `nextPageCursor` for…
Package files Action List the files published in a package using the `package_files` tool from Socket. Returns a tree of paths and sizes for any package on a supported ecosystem (npm, pypi, gem, cargo, maven, golang, nuget, chrome, openvsx). Useful for inspecting what a dependency ships before…

Toolboxes

Each team gets its own Socket toolbox.

Security sees alerts, engineering sees scores, each scoped to the work they do.

  • Security
  • Engineering
  • Platform
  • Incident response
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

Socket · alerts and threat feed

Socket starter 18 Mar 4, 2026

Engineering toolbox

Socket · dependency scores and package files

— 9 Mar 2, 2026

Platform toolbox

Socket · organizations and alerts

— 24 Feb 27, 2026

Incident response toolbox

Socket · package file contents and threat feed

Socket starter 6 Feb 19, 2026

Compliance toolbox

Socket · package risk reviews

— 31 Jan 30, 2026

Open source office toolbox

Socket · library comparisons and scores

— 12 Jan 22, 2026

Shared connections

Share Socket without sharing a token.

One person connects, teams and members work through it, nobody sees a credential.

  • Security
  • Platform
  • Backend
  • Frontend
ElaichiConnections
Connection Scope Status Access
SO

Socket (Security)

Connected by Emily Carter

Personal • Active 1 team · 6 members
SO

Socket (Platform)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
SO

Socket (Backend)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
SO

Socket (Frontend)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
SO

Socket (Compliance)

Connected by Ryan Hayes

Personal • Active Not shared
SO

Socket (Incident response)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every Socket lookup is on the record.

When, who, what happened and which package, in an append-only log.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

[email protected]

Socket Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

[email protected]

Socket Alerts Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

[email protected]

Socket Alerts List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

Socket alerts become a reviewed digest on schedule.

A trigger fetches alerts, groups them, drafts a digest, and a person approves before posting.

Socket digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch alerts

    Socket

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Socket

    Queued

Collections and dashboards

Socket alert counts, computed with no model involved.

Four metrics, fourteen days of alerts created, a breakdown by team, refreshed on a schedule.

Socket health

Refreshed 4 minutes ago · every 15 minutes · from the alerts collection

Live

Alerts

1,284 ↓ 12%

Packages

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Alerts created

Last 14 days

By team

Share of activity

Security 34%

Platform 27%

Backend 21%

Frontend 18%

FAQ

Frequently asked questions

How do I connect Socket to Claude?

Connecting Socket to Claude takes two steps. In Elaichi, choose Socket and sign in over OAuth, which means approving access on Socket's own sign-in page, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp.

Does Socket work with ChatGPT and Cursor as well as Claude?

Yes. Once Socket is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Socket once and every client picks it up.

What can an AI agent actually do with my Socket data?

With Socket connected, an agent can look up the dependency score for a package and version, read the open alerts in your Socket organization, scan the threat feed for newly flagged packages, and list the files inside a package, open one, or search its contents for a word or domain. Short, specific asks such as a package name and version work better than long sentences.

Does connecting Socket give the AI everything in my organization?

No. Every call to Socket runs as the person who signed in, so the agent sees only the Socket organizations, alerts and packages that person can already see. Elaichi can narrow that further with roles and restrictions, and it can never widen it beyond what Socket itself grants.

Can my team share one Socket connection?

Yes. One person connects Socket in Elaichi and shares the connection with a team, and nobody else ever handles a token or credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every Socket lookup.

Can I stop an agent from deleting or changing things in Socket?

Yes. Restrictions in Elaichi apply per action, so you can allow reading Socket alerts and scores while blocking anything you do not want an agent to touch. A restricted action is never advertised to Claude, ChatGPT or Cursor at all, so no prompt can reach it.

What happens to a Socket connection when someone leaves?

When you offboard someone in Elaichi, their access to Socket through every AI client ends at once. A Socket connection they shared keeps working for everyone else on the team. If you ever want Socket gone entirely, disconnecting it once in Elaichi removes it from every client.

Does the Socket MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Socket is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for Socket?

Yes. Both let Claude, ChatGPT or Cursor use Socket. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Socket call.

How is Elaichi different from Composio for Socket?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Socket: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put Socket in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.