# Sprinto MCP connector

Connect Sprinto to Claude, ChatGPT, Cursor and any MCP client through Elaichi, so your team can check compliance status, controls, audits, policies, vendors and risks, and create risks or onboard staff, with every call logged.

Source: https://elaichi.ai/connectors/sprinto-us/

## Facts

| | |
| --- | --- |
| Application | Sprinto |
| Category | Compliance |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Regions | US, EU, India and AU. Elaichi supports all of them; you pick your region when you connect. |
| Native MCP | Yes. Sprinto builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support@sprinto.com |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## Why connect Sprinto's MCP server through Elaichi

Sprinto builds and runs this MCP server. Elaichi sits in front of it, so Sprinto's tools follow the same sign-in, access rules and audit log as every other connector your organization uses. Calls an AI client makes to Sprinto's server directly, outside Elaichi, get none of this.

- **One address for every AI client.** Claude, ChatGPT and Cursor reach Sprinto's tools at https://api.elaichi.ai/mcp, the same address as every other connected app. Nobody adds Sprinto's server to each client one by one.
- **Each person signs in as themselves.** Each person signs in to Elaichi as themselves. Members connect with their own Sprinto sign-in, and a connection someone shares runs on its owner's account. The credential stays in Elaichi's separate credential service, and the AI client holds only its Elaichi sign-in.
- **Rules checked before a call leaves.** Restrictions on a role or a person, for the whole connector or a single tool, are checked before a call reaches Sprinto's server. By default, a tool Sprinto does not mark read-only or non-destructive counts as destructive, and over MCP it needs the "Delete data and remove access" consent.
- **One audit log for every app.** Each call that runs is recorded with the person, the tool, the connection and the AI client that made it, in the same audit log as every other app.
- **Tool issues go to Sprinto.** Sprinto builds and runs these tools, and Elaichi staff do not curate them, so a report about how a tool behaves goes to the Sprinto team. Contact: [support@sprinto.com](mailto:support@sprinto.com).

More: [why run a vendor's MCP server through Elaichi](https://elaichi.ai/blog/vendor-mcp-servers-through-elaichi/)

## What you can ask once Sprinto is connected

- Which controls are failing ahead of our SOC 2 audit?
- List vendors with a security review due this quarter.
- Create a risk for the unpatched laptops finding.

## Connect Sprinto in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Sprinto.
2. Optionally set Share with, then press Connect.
3. Approve it in Sprinto. Sprinto's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Sprinto tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Sprinto MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Sprinto MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Sprinto MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Sprinto to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Every scope the client asks for starts ticked except "Delete data and remove access", which you tick yourself. Calling a Sprinto tool needs "Run your connected tools". Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Sprinto through Elaichi

### Know where the audit stands before the auditor asks

Compliance. Ask which controls are still failing and which evidence is missing for the SOC 2 or ISO 27001 audit in Sprinto, then get a plain list to work through.

### Catch failing controls the day they fail

Security. Check which controls in Sprinto dropped out of compliance this week and who owns them, instead of waiting for the next review meeting.

### Onboard a new hire into compliance on day one

People. Add a new US employee to Sprinto so their policy acknowledgments and training show up on their first morning, not after someone remembers.

### Review a vendor before the renewal lands

Procurement. Pull up a vendor's status and risk rating in Sprinto before signing the renewal, so the security review is not an afterthought.

### Log a risk the moment it surfaces

Leadership. When a meeting turns up a new risk, create it in Sprinto on the spot with the owner and severity, rather than leaving it in a notes app.

### Update a policy and confirm it took

Legal. Push the revised wording of an access control policy into Sprinto and check it is marked current, all from the same conversation.

## Elaichi vs Zapier MCP vs Composio for Sprinto

All three can connect Sprinto to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Sprinto tools | Allow or restrict single Sprinto tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Sprinto call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Sprinto to Claude?

Connect Sprinto in Elaichi first: you sign in to Sprinto over OAuth, approve the access it asks for, and the connection is live. There is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude signs in to Elaichi and Sprinto appears in its tool list.

### Does Sprinto work with ChatGPT and Cursor as well as Claude?

Yes. Once Sprinto is connected in Elaichi, Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent all use the same endpoint, https://api.elaichi.ai/mcp. You connect Sprinto once and every client picks it up.

### What can an AI agent actually do with my Sprinto data?

It can check your compliance status, controls, audits, policies, vendors and risks in Sprinto and answer questions about them in plain language. It can also take actions, such as creating a risk, updating a policy or onboarding a new US staff member. Short, specific asks work best, for example which controls are failing this week, rather than a long paragraph.

### Does connecting Sprinto give the AI everything in my workspace?

No. Every call to Sprinto runs as the person who signed in, so the AI sees only the controls, audits, vendors and risks that person can already see in Sprinto. Elaichi can narrow that access further with restrictions, and it can never widen it beyond what Sprinto itself allows.

### Can my team share one Sprinto connection?

Yes. One person connects Sprinto in Elaichi and shares it with a team, and nobody else ever handles a credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person who checked a control or created a risk in Sprinto.

### Can I stop an agent from deleting or changing things in Sprinto?

Yes. Restrictions in Elaichi work per action, so you can allow reading controls and audits in Sprinto while blocking anything that updates a policy or creates a risk. A restricted action is left out of the AI client's tool list entirely, so it cannot be called no matter what the prompt says.

### What happens to a Sprinto connection when someone leaves?

Offboarding that person in Elaichi ends their access to Sprinto through every AI client at once. A connection they shared with a team keeps working for everyone else. If you want Sprinto gone entirely, disconnect it once in Elaichi and it disappears from Claude, ChatGPT, Cursor and every other client.

### Does the Sprinto MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Sprinto is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Sprinto?

Yes. Both let Claude, ChatGPT or Cursor use Sprinto. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Sprinto call.

### How is Elaichi different from Composio for Sprinto?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Sprinto: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.
