# WorkOS MCP connector

The WorkOS connector brings organizations, SSO connections, users and environments into Claude, ChatGPT, Cursor and the Elaichi Agent, so each person works in WorkOS under their own dashboard role and every action is logged.

Source: https://elaichi.ai/connectors/workos/

## Facts

| | |
| --- | --- |
| Application | WorkOS |
| Category | SSO |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. WorkOS builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support@workos.com |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once WorkOS is connected

- Which organizations have an SSO connection that is not active yet?
- List users added to the Acme organization this month
- Show the connections configured in the staging environment

## Connect WorkOS in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick WorkOS.
2. Optionally set Share with, then press Connect.
3. Approve it in WorkOS. WorkOS's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which WorkOS tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## WorkOS MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## WorkOS MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## WorkOS MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect WorkOS to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a WorkOS tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with WorkOS through Elaichi

### See which organizations have SSO set up

IT. Ask for the organizations in your WorkOS account and which of them have a working connection, without clicking through each one in the dashboard.

### Get an enterprise customer onto single sign-on

Customer Success. Look up the customer's organization in WorkOS, check whether their connection is active, and catch the record up after the setup call.

### Find out why a user cannot sign in

Support. Pull up the user in WorkOS, see which organization and connection they belong to, and spot what is missing before replying to the ticket.

### Review connections before an audit

Security. List the SSO connections across every organization in WorkOS and ask which ones are inactive, so the review starts from facts rather than memory.

### Compare staging and production environments

Platform. Ask what is configured in each WorkOS environment and where they differ, before a release goes out.

### Answer the SSO question on an enterprise deal

Sales. Check in WorkOS whether the prospect's organization already exists and whether a connection is ready, so the answer in the deal review is accurate.

## Elaichi vs Zapier MCP vs Composio for WorkOS

All three can connect WorkOS to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over WorkOS tools | Allow or restrict single WorkOS tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per WorkOS call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect WorkOS to Claude?

In Elaichi, pick WorkOS and connect it: you sign in with your WorkOS dashboard account and approve the request, and there is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. WorkOS is then available in Claude under your own dashboard role.

### Does WorkOS work with ChatGPT and Cursor as well as Claude?

Yes. Once WorkOS is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect WorkOS once and every client uses that one connection.

### What can an AI agent actually do with my WorkOS data?

It can look up the organizations in your WorkOS account, see which ones have an active SSO connection, find a user and the organization they belong to, and compare what is set up in each environment. What it can reach depends on what your WorkOS account has set up, so it matches your dashboard rather than a fixed list. Short, concrete asks such as "which organizations have no active connection" work better than long sentences.

### Does connecting WorkOS give the AI access to everything in my dashboard?

No. Access follows the person who signed in, so an agent working through WorkOS can see and change only what that person's own dashboard role allows. Elaichi can narrow that further with roles and restrictions, and it never widens it.

### Can my team share one WorkOS connection?

Yes. One person connects WorkOS in Elaichi and shares it with a team, and nobody else on the team ever handles a credential. Each person still signs in to Elaichi as themselves, so the audit log names who did what in WorkOS.

### Can I stop an agent from deleting or changing things in WorkOS?

Yes. Restrictions in Elaichi work per action, so you can allow reading organizations, connections and users in WorkOS while blocking anything that changes or removes them. A restricted action is never advertised to Claude, ChatGPT or Cursor, so no prompt can reach it.

### What happens to a WorkOS connection when someone leaves?

Offboarding that person in Elaichi ends their access to WorkOS through every client at once. A WorkOS connection shared with a team keeps working for everyone else. If you want it gone entirely, disconnecting WorkOS once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client.

### Does the WorkOS MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. WorkOS is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for WorkOS?

Yes. Both let Claude, ChatGPT or Cursor use WorkOS. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every WorkOS call.

### How is Elaichi different from Composio for WorkOS?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to WorkOS: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.
