# Upstash MCP connector

The Upstash connector brings your Redis databases, backups, QStash schedules, message queues and vector indexes to Claude, ChatGPT, Cursor and the Elaichi Agent, so each person works with them under their own access and every action is logged.

Source: https://elaichi.ai/connectors/upstash/

## Facts

| | |
| --- | --- |
| Application | Upstash |
| Category | Database |
| AI tools | 55 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Upstash builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support@upstash.com |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Upstash is connected

- Which Redis databases have no backup from this week?
- Show me what is sitting in the dead letter queue.
- Pause the nightly report schedule in QStash until Monday.

## Connect Upstash in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Upstash.
2. Optionally set Share with, then press Connect.
3. Approve it in Upstash. Upstash's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Upstash tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Upstash MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Upstash MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Upstash MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Upstash to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Upstash tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Upstash through Elaichi

### Check a Redis database before a launch

Platform. Ask for memory use, request counts and eviction settings on the database behind tomorrow's release, and get a plain answer without opening the console.

### Take a backup before a risky change

Engineering. Have the agent create a backup of the sessions database, confirm it finished, and list the recent backups so you know there is something to roll back to.

### Clear the dead letter queue after an outage

Operations. See which messages landed in the dead letter queue overnight, decide what to retry or drop, and clear it once the downstream service is back.

### Pause a QStash schedule for the weekend

Engineering. Pause the nightly export schedule before a maintenance window, then resume it on Monday, without hunting for the schedule in the dashboard.

### See what a vector index holds

Data. Ask how many vectors are in the product search index, what dimension it uses, and when it was last updated before you point a new feature at it.

### Trace a failed message through the logs

Support. When a customer reports a missing webhook, pull the QStash logs for that message and find out whether it was delivered, retried or dropped.

## Elaichi vs Zapier MCP vs Composio for Upstash

All three can connect Upstash to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Upstash tools | Allow or restrict single Upstash tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Upstash call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Upstash to Claude?

Connect Upstash in Elaichi first, signing in to your Upstash account over OAuth with no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. Claude asks you to sign in to Elaichi and your Upstash connection is ready to use.

### Does Upstash work with ChatGPT and Cursor as well as Claude?

Yes. Once Upstash is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Upstash once and every client picks it up.

### What can an AI agent actually do with my Upstash data?

An agent connected to Upstash can list your Redis databases, report their memory and request stats, take or list backups, create or rename a database, and run a command against one. It can also publish messages and manage schedules in QStash, read logs, clear a dead letter queue, and tell you what a vector index holds. Short concrete asks work best, such as 'back up the sessions database' rather than a long paragraph.

### Does connecting Upstash give the AI access to every database in my account?

No more than you already have. The AI works inside the Upstash access of the person who signed in, so it sees only the databases, schedules and indexes that person can see. Elaichi can narrow that further with roles and restrictions, and it never widens it.

### Can my team share one Upstash connection?

Yes. One person connects Upstash in Elaichi and shares the connection with a team, and nobody else ever handles the Upstash credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the person who ran each command, not the account owner.

### Can I stop an agent from deleting or changing things in Upstash?

Yes. Restrictions in Elaichi apply per action, so you can allow reading database stats and listing backups while blocking deleting a database, changing eviction settings or clearing a queue. A restricted Upstash action is never advertised to the AI client at all, so no prompt can reach it.

### What happens to an Upstash connection when someone leaves?

Offboarding that person in Elaichi ends their access to Upstash through every client at once. A shared Upstash connection keeps working for everyone else on the team. If you want the connection gone entirely, disconnect Upstash once in Elaichi and it disappears from Claude, ChatGPT, Cursor and every other client.

### Does the Upstash MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Upstash is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Upstash?

Yes. Both let Claude, ChatGPT or Cursor use Upstash. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Upstash call.

### How is Elaichi different from Composio for Upstash?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Upstash: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 55 Upstash tools

Every tool below is callable through https://api.elaichi.ai/mcp once Upstash is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Redis list databases** (List). Every Redis database in the account scope
- **Redis get database** (Get). One database in detail; REST credentials with `include_credentials`
- **Redis get stats** (Get). Throughput, data size, hit and miss counts
- **Redis list backups** (List). Backups taken of a database
- **Redis create database** (Create). Creates a database; returns its credentials with `include_credentials`
- **Redis create backup** (Create). Takes a manual backup
- **Redis rename database** (Action). Renames a database, replacing its current name
- **Redis set eviction** (Set). Turns key eviction on or off
- **Redis set auto upgrade** (Set). Turns automatic plan upgrade on or off
- **Redis delete database** (Delete). Deletes a database and everything in it
- **Redis run command** (Run). Runs Redis commands over the REST API, one or a pipeline
- **Qstash list users** (List). The QStash user per region; REST tokens and signing keys with `include_credentials`
- **Qstash list schedules** (List). Schedules in a region
- **Qstash flow control get** (Get). Rate and parallelism for a flow-control key, or the account's global parallelism
- **Logs list** (List). Delivery and run logs, paginated by cursor
- **Dlq list** (List). The dead-letter queue, paginated by cursor
- **Qstash publish message** (Publish). Publishes a message to a destination URL
- **Qstash flow control manage** (Action). Pauses, resumes, pins, unpins or resets the rate on a key
- **Qstash manage schedule** (Action). Creates, reads, deletes, pauses or resumes a schedule
- **Workflow manage run** (Run). Reads a run's steps, or cancels the run
- **Dlq manage** (Action). Reads or deletes a DLQ entry; Workflow entries can also be restarted or resumed
- **Index list** (List). Every Vector index or Search database in the account scope
- **Index get** (Get). One of them in detail; REST tokens with `include_credentials`
- **Index info** (Action). Document counts, index size, per-namespace breakdown
- **Index list namespaces** (List). Namespaces, which for Search are its named indexes
- **Index fetch** (Action). Documents by ID or ID prefix
- **Index range** (Action). Pages through the documents of a namespace
- **Index create** (Create). Creates a Vector index or a Search database; tokens with `include_credentials`
- **Index update** (Update). Edits one document in place, including a metadata patch mode
- **Index rename namespace** (Action). Renames a namespace
- **Index delete** (Delete). Deletes an index or database and everything in it
- **Index delete documents** (Delete). Deletes documents by ID, prefix or filter
- **Index reset** (Action). Empties a namespace, or every namespace, keeping the index
- **Index delete namespace** (Delete). Deletes a namespace and its contents
- **Vector query** (Search). Vector similarity search, with server-side embedding optional
- **Search query** (Search). Full-text and semantic search over one named index
- **Vector upsert** (Upsert). Upserts vectors, or text for the server to embed; an existing ID is overwritten
- **Search upsert** (Search). Upserts documents, creating the named index if needed; an existing ID is overwritten
- **Box logs** (Action). Timestamped log entries from a box, filterable by source, level, text and time window
- **Box metrics** (Action). `current`, `history`, `tokens`, `steps`, `step_diff` — CPU, memory and disk for one box, token spend by day, and the steps of an agent run with their diffs
- **Box account** (Action). `summary`, `billing`, `logs` — each active box with its cost (`status: deleted` for the deleted ones), this month's totals, and log lines across all boxes
- **Box browser** (Action). `goto`, `content`, `screenshot`, `tabs`, `tab_new`, `tab_close`, `live_view` — needs a box created with `browser: true`
- **Box git** (Action). `clone`, `status`, `diff`, `commit`, `checkout`, `push`, `create_pr`, `create_issue` — authenticated by the GitHub installation linked to the account
- **Box manage** (Action). `create`, `list`, `get`, `status`, `delete`, `pause`, `resume`, `fork`, `reset` — `delete` takes one `box_id` or up to 50 `box_ids`; `create` also takes `init_command`, `skills`, `network_policy`, `attach_headers`, `mcp_servers` and a git identity
- **Box exec** (Action). Runs a shell command (argv array, optional `folder`) and waits for it; an inline program is `['node', '-e', code]` or `['python3', '-c', code]`
- **Box schedules** (Action). `create`, `list`, `get`, `update`, `pause`, `resume`, `delete` — cron schedules that run a `command` or an agent `prompt` in a box
- **Box config** (Action). `get`, `set_model`, `add_label`, `remove_label`, `add_skill`, `remove_skill`, `add_mcp_server`, `remove_mcp_server`, `set_network_policy`, `set_git_identity`, `get_init_command`, `set_init_command`, `delete_init_command` — settings of a running box
- **Box env** (Action). `list`, `set`, `set_all`, `delete` — account-level environment variables, merged into every box created afterwards
- **Box preview** (Action). `create`, `list`, `delete` — public URLs for ports in a box
- **Box runs** (Action). `list`, `get`, `cancel` — a box's run history
- ...and 5 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
