# Sprinto MCP connector

The Sprinto connector lets Claude, ChatGPT, Cursor, and other AI clients list your Sprinto workflow checks, attach evidence, create background verification reports, and mark staff in or out of scope, all inside each person's own Sprinto access.

Source: https://elaichi.ai/connectors/sprinto/

## Facts

| | |
| --- | --- |
| Application | Sprinto |
| Category | Compliance |
| AI tools | 5 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | Yes |

## What you can ask once Sprinto is connected

- Which Sprinto workflow checks are failing this week?
- Attach evidence to the access review workflow check.
- Mark new joiners in scope in Sprinto.

## Connect Sprinto in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Sprinto.
2. Optionally set Share with, then press Connect.
3. Paste a Sprinto API key. One person generates a token in Sprinto and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Sprinto tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Sprinto to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Sprinto to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Sprinto to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Sprinto to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Sprinto tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Sprinto through Elaichi

### See which checks still need attention

Compliance. Ask for every workflow check in Sprinto and get a plain list of what is passing, what is failing, and what is waiting on someone, without opening the dashboard.

### Attach evidence the moment work is done

Security. After a review or a fix is finished, add the evidence to the right Sprinto workflow check while it is still fresh, instead of leaving it for the week before the audit.

### Start a background check for a new hire

People. When someone accepts an offer, create their background verification report in Sprinto as part of the onboarding checklist, so the record exists before day one.

### Bring new staff into compliance scope

IT. When a new employee or contractor is added, mark them in scope in Sprinto so their laptop, training, and policy acceptance start being tracked right away.

### Take leavers and contractors out of scope

Operations. When someone leaves or a contractor's engagement ends, mark them not in scope in Sprinto so they stop generating failing checks for a role they no longer hold.

### Prepare for the audit window without scrambling

Engineering. Pull the current state of Sprinto workflow checks into a summary for the audit lead, then attach the evidence that engineering owns as each item is closed.

## Frequently asked questions

### How do I connect Sprinto to Claude?

Connect Sprinto in Elaichi first, then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Sprinto connects with an API key, so the sign-in step is copying a key from your Sprinto settings into Elaichi. There is no OAuth application to register and no client ID or secret to generate.

### Does Sprinto work with ChatGPT and Cursor as well as Claude?

Yes. Once Sprinto is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Sprinto once and every client you use picks it up.

### What can an AI agent actually do with my Sprinto data?

With Sprinto connected, an agent can list your workflow checks and tell you which ones are failing or waiting, attach evidence to a check when work is finished, and create a background verification report for a new hire. It can also mark staff members in scope or not in scope as people join, change roles, or leave. It does what a compliance owner would do by hand in Sprinto, just from a conversation.

### Does connecting Sprinto give the AI access to my whole compliance program?

No. Every call to Sprinto runs as the person who signed in, so an agent sees and changes only what that person could already see and change in Sprinto. Elaichi can narrow that further, for example limiting someone to viewing checks and attaching evidence, but it can never widen access beyond what Sprinto itself grants that person.

### Can my team share one Sprinto connection?

Yes. One person connects Sprinto in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person who listed a check, attached evidence, or changed someone's scope in Sprinto.

### Can I stop an agent from changing things in Sprinto?

Yes. Restrictions in Elaichi work per action, so you can allow listing Sprinto workflow checks while blocking the ability to change staff scope or create reports. A blocked action is never advertised to Claude, ChatGPT, Cursor, or any other client, so no prompt, however worded, can reach it.

### What happens to a Sprinto connection when someone leaves?

Offboarding the person in Elaichi ends their access to Sprinto through every AI client at once. If they had shared a Sprinto connection with the team, it keeps working for everyone else. If you want Sprinto gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.

## All 5 Sprinto tools

Every tool below is callable through https://api.elaichi.ai/mcp once Sprinto is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Sprinto workflow checks** (List). List workflow checks in Sprinto using cursor-based pagination. Returns a paginated collection of workflow check edges, each containing a node with the check's pk and title, plus a cursor string used for page navigation.
- **Create a Sprinto background verification report** (Create). Upload a background verification report for a staff member in Sprinto. Returns: message. Required: email, verificationCompletedOn, verificationReportFile.
- **Create a Sprinto workflow check evidence** (Create). Upload evidence for a workflow check in Sprinto. Returns workflowCheck containing the evidenceStatus of the check after the upload. Required: workflowCheckPk, evidenceRecordDate, evidenceFile.
- **Sprinto staff members mark in scope** (Action). Mark a Sprinto staff member account as in-scope, including them in the audit compliance scope so they are mapped against configured controls and automated checks. Returns a user object containing pk, firstName, lastName, fullName, and email. Required: email.
- **Sprinto staff members mark not in scope** (Action). Mark a Sprinto staff member account as not in-scope, excluding them from the audit compliance scope so Sprinto does not perform security tasks (such as policy acceptance or training) for that account. Returns a user object containing pk, firstName, lastName, fullName, and email. Required: email. Optional: reason.
