# Wiz MCP connector

The Wiz connector brings Wiz issues, vulnerability findings, detections, projects, exposed resources and reports into Claude, ChatGPT, Cursor and any MCP client, so your team can ask about cloud security posture in plain language.

Source: https://elaichi.ai/connectors/wiz/

## Facts

| | |
| --- | --- |
| Application | Wiz |
| Category | Security |
| AI tools | 18 |
| Authentication | App credentials |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | Yes |

## What you can ask once Wiz is connected

- Show critical Wiz issues opened this week by project
- Which exposed resources have unresolved vulnerability findings?
- Summarize configuration findings for the payments project

## Connect Wiz in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Wiz.
2. Optionally set Share with, then press Connect.
3. Paste your Wiz app credentials. Wiz authenticates the app rather than a person. One person supplies the credentials once, and everyone else works through Share with.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Wiz tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Wiz to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Wiz to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Wiz to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Wiz to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Wiz tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Wiz through Elaichi

### Triage this morning's critical issues

Security. Ask which Wiz issues opened overnight at critical severity, which projects they touch and whether any resource is publicly exposed, then decide who picks up what before standup.

### Find the vulnerabilities on a workload

Cloud engineering. Pull the vulnerability findings for one cloud resource or one project and get them grouped by severity and fix availability so the patching plan writes itself.

### Check a repository before the release

DevOps. List the code scan findings and peer review enforcement findings for a version control repository so the release owner knows what is blocking sign-off.

### Gather evidence for the audit

Compliance. Collect the backup findings, firewall findings and infrastructure logging findings for a project into one summary that maps to the control you are being asked about.

### Review who has access to Wiz

IT. List Wiz users and recent audit log entries to confirm that the right people hold access and to spot accounts that should have been removed.

### Summarize exposure for the weekly review

Leadership. Ask for exposed resources, open detections and configuration findings across all projects, and get a short readout you can paste into the weekly security review.

## Frequently asked questions

### How do I connect Wiz to Claude?

Connect Wiz in Elaichi first, then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. The Wiz sign-in step asks for the app credentials from your Wiz tenant, and there is no OAuth application to register and no client ID or secret to generate. Once both steps are done, Claude can read Wiz issues, findings and projects as you.

### Does Wiz work with ChatGPT and Cursor as well as Claude?

Yes. The Wiz connector sits behind one endpoint, https://api.elaichi.ai/mcp, and Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent all connect to that same address. You connect Wiz once in Elaichi and every client you use picks it up.

### What can an AI agent actually do with my Wiz data?

With Wiz connected, an agent can list issues, detections, vulnerability findings and configuration findings, look up projects, resources and exposed resources, and read reports and audit logs. It can also pull findings for code scans, firewalls, backups, application and infrastructure logging, and peer review enforcement, and open a single system activity by its ID. This connector reads from Wiz; it does not change anything in your Wiz tenant.

### Does connecting Wiz give the AI access to every project in my tenant?

No. Every request to Wiz runs inside the access of the person who signed in, so an agent sees the projects, issues and findings that person can already see in Wiz and nothing beyond that. Elaichi can narrow that further, for example to a subset of the connector's abilities, but it can never widen what Wiz itself allows.

### Can my team share one Wiz connection?

Yes. One person connects Wiz in Elaichi and shares the connection with a team, and nobody else on that team ever handles the Wiz app credentials. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every look at a Wiz issue or finding.

### Can I stop an agent from deleting or changing things in Wiz?

The Wiz connector only lists and reads records, so an agent cannot delete or change issues, projects or findings through it. Beyond that, Elaichi restrictions work per action, so you can also hide particular Wiz abilities, such as reading audit logs or user lists, from a team. A blocked action is never advertised to the AI client, so no prompt can reach it.

### What happens to a Wiz connection when someone leaves?

Offboarding a person in Elaichi ends their access to Wiz through every client at once, whether Claude, ChatGPT, Cursor or the Elaichi Agent. If they connected a shared Wiz connection, it keeps working for everyone else on the team. Disconnecting Wiz once in Elaichi removes it from every client, with no per-client cleanup.

## All 18 Wiz tools

Every tool below is callable through https://api.elaichi.ai/mcp once Wiz is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Wiz users** (List). List users in Wiz. Returns user details including name, email, and last_login.
- **List all Wiz projects** (List). List all projects in Wiz. Returns id, name, isFolder, nestingLevel, archived, businessUnit, and description for each project.
- **List all Wiz audit logs** (List). Get audit log entries in Wiz. Returns fields id, action, requestId, status, timestamp, actionParameters, userAgent, sourceIP, serviceAccount, and user.
- **List all Wiz configuration findings** (List). List configuration findings in Wiz. Returns fields such as id, severity, status, remediation, resource details (id, name, type), rule information, and securitySubCategories.
- **List all Wiz resources** (List). List cloud resources in Wiz. Returns key fields including id, name, type, technology, cloudAccount, status, region, tags, and visibility flags. Fields firstSeen and lastSeen may be null.
- **List all Wiz issues** (List). List issues in Wiz. Returns each issue's id, severity, status, createdAt, updatedAt, related entitySnapshot details (id, type, name), sourceRules with descriptions, and linked projects, notes, and serviceTickets.
- **List all Wiz detections** (List). List detections in Wiz. Returns fields such as id, type, severity, origins, actors, resources, primaryResource, and ruleMatch. Each detection is generated by Threat Detection Rules. API limited to one pull every 5 minutes; triggering events capped at 50 per detection.
- **List all Wiz version control repositories** (List). List version control repositories in Wiz. Returns repository id, platform, providerID, type, and details including repository name and URL.
- **List all Wiz exposed resources** (List). List exposed-resources in Wiz. Returns fields such as id, exposedEntity details (id, name, type, properties), accessibleFrom, path, sourceIpRange, destinationIpRange, portRange, protocols, firstSeenAt, and applicationEndpoints.
- **Get single Wiz system activity by ID** (Get). Get details about a specific system activity in Wiz using id. Returns status, statusInfo, result details (dataSources, findings, events, tags, unresolvedAssets), and context with fileUploadId.
- **List all Wiz vulnerability findings** (List). List vulnerability findings in Wiz. Returns fields such as id, name, severity, score, exploitabilityScore, status, affected assets, remediation, and timestamps. This API supports incremental pulls for recent vulnerabilities only.
- **List all Wiz reports** (List). List reports in Wiz. Returns report fields including id and name.
- **List all Wiz firewall findings** (List). List firewall findings in Wiz. Returns id, severity, result, status, remediation, associated resource details, rule info, and security categories.
- **List all Wiz backup findings** (List). List backup findings in Wiz. Returns id, severity, result, status, remediation, resource details, rule information, and related security categories for each configuration finding.
- **List all Wiz code scan findings** (List). List code scan findings in Wiz. Returns fields such as id, severity, result, status, remediation details, and related resource, rule, and security category information.
- **List all Wiz application logging findings** (List). List application logging findings in Wiz. Returns fields such as id, severity, result, status, and remediation, along with resource, rule, and securitySubCategories details.
- **List all Wiz infrastructure logging findings** (List). Get a list of infrastructure logging findings in Wiz. The response includes id, severity, result, status, remediation details, resource metadata, rule details, and security categories.
- **List all Wiz peer review enforcement findings** (List). List peer review enforcement findings in Wiz. Returns fields such as id, targetExternalId, severity, result, status, and resource details including provider, region, and associated projects.
