Skip to content

Application Development

Unkey MCP connector

The Unkey connector lets Claude, ChatGPT, Cursor, and the Elaichi Agent create and manage API keys, identities, permissions, and deployments in Unkey as the signed-in person, with every action recorded in an audit log.

  • How it connects. Connects with an API key. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Unkey to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Unkey once

  1. Open Connections, choose Add connection, and pick Unkey.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste an Unkey API key. One person generates a token in Unkey and pastes it once. Everyone else works through Share with, and never sees it.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

unkey
Unkey
Apache Airflow
Boomi
Browserbase
Caspio
Cloudflare
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect Unkey to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect Unkey to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect Unkey to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Unkey to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Unkey through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Engineering

    Issue a key for a new customer

    Ask for a new Unkey key tied to a customer's identity, with the right roles and permissions set from the start, without opening the dashboard.

  • Support

    Look up a key a customer is asking about

    Paste the key a customer sent in and get back which identity it belongs to, what it is allowed to do, and whether it still exists.

  • Security

    Reroll a key that leaked

    When a key shows up somewhere it should not, ask for it to be rerolled or deleted in Unkey right away, and confirm the old one is gone.

  • Platform

    Adjust roles and permissions in bulk

    Add, remove, or replace the roles and permissions on a set of Unkey keys when a plan changes or a feature moves tiers.

  • Product

    See how often keys are being verified

    Pull verification analytics from Unkey to find out which customers are actively calling your API and which have gone quiet.

  • Customer Success

    Keep customer identities up to date

    Update an identity's details in Unkey after a renewal or a name change, and list identities to check which accounts still have active keys.

Try asking

  • “List keys created for the Payments API this week.”
  • “Which identities have admin roles on production keys?”
  • “Show verification counts by API for the last 14 days.”

See all 47 Unkey tools below

AI tools

Unkey tools for your AI agents

47 tools are ready to call through Elaichi's MCP endpoint the moment you connect Unkey, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Unkey gets you

6 screens from the product, each doing one job for your Unkey account.

The agent

Ask about keys, get real answers.

Plain questions return live Unkey keys, APIs and verification counts.

  • keys
  • apis
  • identities
  • deployments

Ask Elaichi to work across your apps.

List keys created for the Payments API this week.

Which identities have admin roles on production keys?

Show verification counts by API for the last 14 days.

Also runs in Claude, ChatGPT or Cursor

MCP clients

One Unkey endpoint, every MCP client.

Claude, ChatGPT and Cursor connect over OAuth, no SDK, no shared key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

47 Unkey tools, no custom code.

APIs, keys, identities, deployments and analytics, each with listed methods and resources.

  • Unkey analytics get verifications
  • Create a Unkey API
  • Delete a Unkey API by ID
  • Get single Unkey API by ID
ElaichiTools
Tool Action Description
Unkey analytics get verifications Get Execute a SELECT SQL query against key verification analytics in Unkey. Returns a meta object with requestId and a data array of verification rows whose fields match your SQL SELECT clause. Only SELECT queries are allowed. Required: query.
Create a Unkey API Create Create a new API namespace in Unkey. Returns the created namespace's api_id and request metadata. Required: name.
Delete a Unkey API by ID Delete Delete an Unkey API namespace by id. Returns request metadata and an empty data object on success. Required: id.
Get single Unkey API by ID Get Get an Unkey API namespace by id. Returns the API namespace including id and name. Required: id.
Unkey apis list keys List List API keys for an Unkey API namespace. Returns: keyId, start, enabled, name, meta, createdAt, updatedAt, lastUsedAt, expires, permissions, roles, credits, identity, plaintext, ratelimits. Required: apiId.

Toolboxes

Every team gets its own toolbox.

Curate one Unkey toolbox per team, from platform to support.

  • Platform
  • Backend
  • Security
  • Support
ElaichiToolboxes
Name Source template Tools Created

Platform toolbox

Unkey · APIs and deployments

Unkey starter 18 Mar 4, 2026

Backend toolbox

Unkey · keys and permissions

9 Mar 2, 2026

Security toolbox

Unkey · roles and identities

24 Feb 27, 2026

Support toolbox

Unkey · key lookups and verifications

Unkey starter 6 Feb 19, 2026

Developer relations toolbox

Unkey · sandbox keys and quotas

31 Jan 30, 2026

Data toolbox

Unkey · verification analytics

12 Jan 22, 2026

Shared connections

Teammates use Unkey without touching credentials.

Each connection shows who connected it and which teams and members share it.

  • Production
  • Staging
  • Payments API
  • Public API
ElaichiConnections
Connection Scope Status Access
UN

Unkey (Production)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
UN

Unkey (Staging)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
UN

Unkey (Payments API)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
UN

Unkey (Public API)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
UN

Unkey (Internal tooling)

Connected by Clara Nowak

Personal • Active Not shared
UN

Unkey (Sandbox)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Answer who rotated which Unkey key.

Append-only log records when, who, what happened, type and resource.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Unkey Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Unkey Keys Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Unkey Keys List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule fires, work finishes itself.

Fetch Unkey verifications, group them, draft a digest, approve, post back.

Unkey digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch keys

    Unkey

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Unkey

    Queued

Collections and dashboards

Unkey key health, computed on schedule.

Four metrics, 14 days of keys created, and a breakdown by team.

Unkey health

Refreshed 4 minutes ago · every 15 minutes · from the keys collection

Live

Keys

1,284 ↓ 12%

Apis

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Keys created

Last 14 days

By team

Share of activity

Production 34%

Staging 27%

Payments API 21%

Public API 18%

FAQ

Frequently asked questions

How do I connect Unkey to Claude?

Connecting Unkey to Claude takes two steps. First, connect Unkey in Elaichi by pasting a root key from your Unkey dashboard, there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Sign in with your Elaichi account and Unkey is available in Claude.

Does Unkey work with ChatGPT and Cursor as well as Claude?

Yes. Once Unkey is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Unkey once and every client picks it up, with the same access rules and the same audit log.

What can an AI agent actually do with my Unkey data?

An agent connected to Unkey can create, look up, reroll, migrate, and delete API keys, and add, remove, or set the roles and permissions on them. It can create and update identities, create APIs and deployments, list the keys under an API, and pull verification analytics to show who is calling your API. Because Unkey has many available actions, short concrete asks such as "reroll the key for Acme" work better than long paragraphs.

Does connecting Unkey give the AI access to my whole workspace?

No. The AI acts through the Unkey root key the connecting person pasted in, so it can only reach the APIs, keys, and identities that key already covers in Unkey. Elaichi can narrow that further, for example to read-only analytics for one team, but it can never widen access beyond what the person already has.

Can my team share one Unkey connection?

Yes. One person connects Unkey in Elaichi and shares the connection with a team, and nobody else ever handles the Unkey root key. Each teammate still signs in to Elaichi as themselves, so every key created, rerolled, or deleted in Unkey is logged under the name of the person who asked for it.

Can I stop an agent from deleting or changing keys in Unkey?

Yes. Restrictions in Elaichi work per action, so you can allow looking up Unkey keys and reading analytics while blocking deleting keys, deleting APIs, or changing permissions. A blocked action is never advertised to Claude, ChatGPT, or Cursor, so no prompt, however worded, can reach it.

What happens to a Unkey connection when someone leaves?

When a person is offboarded in Elaichi their access to Unkey through every client ends at once. If they had shared the Unkey connection with a team, it keeps working for everyone else on that team. Disconnecting Unkey in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client in one step.

Put Unkey in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.