Skip to content

SSO

WorkOS MCP connector

The WorkOS connector brings organizations, SSO connections, users and environments into Claude, ChatGPT, Cursor and the Elaichi Agent, so each person works in WorkOS under their own dashboard role and every action is logged.

  • How it connects. Connects over OAuth. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect WorkOS to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect WorkOS once

  1. Open Connections, choose Add connection, and pick WorkOS.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Approve it in WorkOS. WorkOS's own window opens. Whoever approves it decides what this connection can reach.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

workos
WorkOS
Auth0
Google
Google Workspace
Okta
Stytch
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

WorkOS MCP connector for Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

WorkOS MCP connector for ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

WorkOS MCP connector for Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect WorkOS to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with WorkOS through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • IT

    See which organizations have SSO set up

    Ask for the organizations in your WorkOS account and which of them have a working connection, without clicking through each one in the dashboard.

  • Customer Success

    Get an enterprise customer onto single sign-on

    Look up the customer's organization in WorkOS, check whether their connection is active, and catch the record up after the setup call.

  • Support

    Find out why a user cannot sign in

    Pull up the user in WorkOS, see which organization and connection they belong to, and spot what is missing before replying to the ticket.

  • Security

    Review connections before an audit

    List the SSO connections across every organization in WorkOS and ask which ones are inactive, so the review starts from facts rather than memory.

  • Platform

    Compare staging and production environments

    Ask what is configured in each WorkOS environment and where they differ, before a release goes out.

  • Sales

    Answer the SSO question on an enterprise deal

    Check in WorkOS whether the prospect's organization already exists and whether a connection is ready, so the answer in the deal review is accurate.

Try asking

  • “Which organizations have an SSO connection that is not active yet?”
  • “List users added to the Acme organization this month”
  • “Show the connections configured in the staging environment”

Compare

Elaichi vs Zapier MCP vs Composio for WorkOS

All three can connect WorkOS to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

Elaichi compared with Zapier MCP and Composio for WorkOS, by what to check
What to check Elaichi Zapier MCP Composio
Where the AI connects One address for the whole organization. https://api.elaichi.ai/mcp A server per member, created at sign-in. An MCP endpoint per team, or an SDK.
Control over WorkOS tools Allow or restrict single WorkOS tools, per role or user. App and action restrictions on the account. Role permissions, down to the action.
Record of calls One audit entry per WorkOS call. A History tab of tool calls. A log of every tool call.
Single sign-on SAML or OIDC, plus SCIM, on Gold. SAML on Enterprise. SAML and OIDC on Enterprise.
Price $15 per user per month. 2 tasks per successful call. Billed per tool call.

Sources: Zapier MCP docs, security, usage; Composio docs, gateway, enterprise, pricing. Checked September 2026.

Longer take: Zapier MCP alternative and when you don't need an MCP gateway.

See it in Elaichi

What connecting WorkOS gets you

5 screens from the product, each doing one job for your WorkOS account.

The agent

Ask about organizations and connections in plain language.

Answers come from live WorkOS records, under your own dashboard role.

  • organizations
  • connections
  • users
  • environments

Ask Elaichi to work across your apps.

Which organizations have an SSO connection that is not active yet?

List users added to the Acme organization this month

Show the connections configured in the staging environment

Also runs in Claude, ChatGPT or Cursor

MCP clients

One governed endpoint for Claude, ChatGPT and Cursor.

Connect WorkOS once and every MCP client uses it, no SDK, no shared key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emily Carter

• Connected 4 minutes ago
Cursor
M

Megan Brooks

• Connected 2 hours ago
ChatGPT
R

Ryan Hayes

• Connected Yesterday

Toolboxes

Each team gets its own WorkOS toolbox.

Security, IT and Customer Success each see only the WorkOS work scoped to them.

  • IT
  • Security
  • Customer Success
  • Support
ElaichiToolboxes
Name Source template Tools Created

IT toolbox

WorkOS · organizations and connections

WorkOS starter 18 Mar 4, 2026

Security toolbox

WorkOS · connection and user review

— 9 Mar 2, 2026

Customer Success toolbox

WorkOS · customer organizations

— 24 Feb 27, 2026

Support toolbox

WorkOS · users and sign-in issues

WorkOS starter 6 Feb 19, 2026

Platform toolbox

WorkOS · environments and connections

— 31 Jan 30, 2026

Sales toolbox

WorkOS · enterprise organizations

— 12 Jan 22, 2026

Shared connections

Teammates work in WorkOS without seeing a credential.

One person connects WorkOS, shares it with teams, and nobody else handles a key.

  • IT
  • Security
  • Customer Success
  • Support
ElaichiConnections
Connection Scope Status Access
WO

WorkOS (IT)

Connected by Emily Carter

Personal • Active 1 team · 6 members
WO

WorkOS (Security)

Connected by Jake Morgan

Organization • Active 3 teams · 24 members
WO

WorkOS (Customer Success)

Connected by Megan Brooks

Organization • Active 2 teams · 11 members
WO

WorkOS (Support)

Connected by Tyler Reed

Personal • Needs re-auth 1 team · 3 members
WO

WorkOS (Platform)

Connected by Ryan Hayes

Personal • Active Not shared
WO

WorkOS (Enterprise Sales)

Connected by Ashley Parker

Personal • Active 2 teams · 9 members

Audit log

Every WorkOS action is on the record.

See who touched which organization, connection or user, and exactly when.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emily Carter

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

Jake Morgan

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

M

Megan Brooks

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

T

Tyler Reed

[email protected]

WorkOS Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

R

Ryan Hayes

[email protected]

WorkOS Organizations Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

A

Ashley Parker

[email protected]

WorkOS Organizations List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule runs WorkOS work end to end.

New connections are fetched, grouped and drafted into a digest a person approves before posting.

WorkOS digest

Run 418 · started 2 minutes ago · on behalf of Emily Carter

  1. ✓

    Schedule

    Every weekday at 8:00 AM

    0.2s
  2. ✓

    Fetch organizations

    WorkOS

    1.4s
  3. ✓

    Group by owner

    Transform

    0.1s
  4. ✓

    Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    WorkOS

    Queued

Collections and dashboards

WorkOS health, computed on a schedule.

Organizations, connections and users created over 14 days, broken down by team, no model involved.

WorkOS health

Refreshed 4 minutes ago · every 15 minutes · from the organizations collection

Live

Organizations

1,284 ↓ 12%

Connections

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Organizations created

Last 14 days

By team

Share of activity

IT 34%

Security 27%

Customer Success 21%

Support 18%

FAQ

Frequently asked questions

How do I connect WorkOS to Claude?

In Elaichi, pick WorkOS and connect it: you sign in with your WorkOS dashboard account and approve the request, and there is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. WorkOS is then available in Claude under your own dashboard role.

Does WorkOS work with ChatGPT and Cursor as well as Claude?

Yes. Once WorkOS is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect WorkOS once and every client uses that one connection.

What can an AI agent actually do with my WorkOS data?

It can look up the organizations in your WorkOS account, see which ones have an active SSO connection, find a user and the organization they belong to, and compare what is set up in each environment. What it can reach depends on what your WorkOS account has set up, so it matches your dashboard rather than a fixed list. Short, concrete asks such as "which organizations have no active connection" work better than long sentences.

Does connecting WorkOS give the AI access to everything in my dashboard?

No. Access follows the person who signed in, so an agent working through WorkOS can see and change only what that person's own dashboard role allows. Elaichi can narrow that further with roles and restrictions, and it never widens it.

Can my team share one WorkOS connection?

Yes. One person connects WorkOS in Elaichi and shares it with a team, and nobody else on the team ever handles a credential. Each person still signs in to Elaichi as themselves, so the audit log names who did what in WorkOS.

Can I stop an agent from deleting or changing things in WorkOS?

Yes. Restrictions in Elaichi work per action, so you can allow reading organizations, connections and users in WorkOS while blocking anything that changes or removes them. A restricted action is never advertised to Claude, ChatGPT or Cursor, so no prompt can reach it.

What happens to a WorkOS connection when someone leaves?

Offboarding that person in Elaichi ends their access to WorkOS through every client at once. A WorkOS connection shared with a team keeps working for everyone else. If you want it gone entirely, disconnecting WorkOS once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client.

Does the WorkOS MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. WorkOS is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

Is Elaichi an alternative to Zapier MCP for WorkOS?

Yes. Both let Claude, ChatGPT or Cursor use WorkOS. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every WorkOS call.

How is Elaichi different from Composio for WorkOS?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to WorkOS: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

Put WorkOS in front of your team

14 days on Gold, no credit card. Connect it once and pick what each team can call.

Works with
Claude ChatGPT Cursor and any other MCP client, or the Elaichi Agent.
When the trial ends
Nothing is deleted. Connections, roles and the audit log stay where they are, so subscribing picks up exactly where you left off.