# WorkOS MCP for AI Agents AI Agent Connect

> WorkOS MCP lets you manage enterprise identity infrastructure through your AI agent. It handles organization records, SSO connections, and directory syncs for platforms like Okta or Azure AD. Instead of clicking through a dashboard, you can audit logs, check connection health, and manage user rosters using natural language. It's built for teams who need to keep their enterprise auth systems organized without the manual overhead.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_rwxMA9lZDQOsPAB4YWRqrtYcwkF7I80gqKgTYNRP/ai-agent-connect
- **Tags:** sso, saml, oidc, directory-sync, audit-logs, enterprise-ready, authentication

## Description

WorkOS MCP lets you manage your enterprise identity infrastructure through natural conversation with your AI agent. This Connector handles the heavy lifting of identity management so you don't have to navigate through complex dashboards or multiple tabs. You can browse your enterprise organizations, create new records, and manage authorized domains using simple chat commands. It handles the details of Single Sign-On connections, allowing you to audit active SAML and OIDC links to ensure your customers can always get into their accounts. If you're tracking directory syncs from providers like Okta or Azure AD, you can monitor those instances and pull deep details on their status. You can also pull complete user rosters and organizational groups directly into your chat. For security and compliance, you can stream audit log events to monitor activities across any organization. It's designed to give you quick insights into organization IDs and connection metadata for faster configuration. By connecting this to your workflow through Vinkius, you turn your AI agent into a dedicated identity administrator. You no longer have to manually check sync statuses or hunt for connection IDs. It's about getting the information you need to keep your enterprise features running smoothly, whether you're troubleshooting a login issue, auditing access, or onboarding a new tenant. You get a direct line to your WorkOS data without leaving your primary workspace, making it much easier to stay on top of your infrastructure.

## Tools

### get_audit_log_events
Retrieve a stream of security and compliance events for a specific organization. Use this to monitor recent activity for security checks.

### get_sso_connection_details
Pull specific metadata and status info for a single SSO connection. This is great for checking if a SAML or OIDC link is active.

### get_directory_details
Get metadata for a specific directory instance like Okta or Azure AD. This helps you verify the status of your directory syncs.

### get_organization_details
Fetch the full details for a specific organization record. Use this to see all the configuration data for a single tenant.

### list_sso_connections
List all active SAML and OIDC connections in your account. This gives you a bird's eye view of your enterprise connections.

### list_directories
View all active Directory Sync instances currently in use. Use this to check the status of your HRIS and SCIM connections.

### create_workos_organization
Create a new organization record with a name and a list of authorized domains. This helps you set up new enterprise tenants quickly.

### list_directory_groups
See all groups currently synced from an external directory. This is useful for auditing user permissions and access.

### list_workos_organizations
Get a complete list of all organizations in your WorkOS account. Use this to find specific organization IDs without manual searching.

### list_directory_users
List all users currently synced from a directory. This allows you to pull a full roster of users into your chat quickly.

## Prompt Examples

**Prompt:** 
```
List all organizations in my WorkOS account.
```

**Response:** 
```
I found 5 organizations:

| Name | ID | Status |
| :--- | :--- | :--- |
| **Acme Corp** | `org_01E...` | Active |
| **Global Tech** | `org_01F...` | Active |
| **Stark Industries** | `org_01G...` | Active |

Would you like to see details for one of these?
```

**Prompt:** 
```
Check the status of SSO connections for 'Acme Corp'.
```

**Response:** 
```
**Acme Corp** (org_01E...) has 2 active SSO connections:

*   **Okta SAML**: Status: **ACTIVE** (ID: conn_01H...)
*   **Azure AD OIDC**: Status: **ACTIVE** (ID: conn_01I...)

Both links are healthy and operational.
```

**Prompt:** 
```
List all users synced from the directory 'dir_01J...'.
```

**Response:** 
```
I found 120 users in directory `dir_01J...`. The most recently synced users are:

1.  **John Doe** (john@acme.com)
2.  **Jane Smith** (jane@acme.com)
3.  **Robert Brown** (robert@acme.com)

Would you like to see the full roster or filter by group?
```

## Capabilities

### Create enterprise organizations
Create new organization records with specific names and authorized domains.

### Audit SSO connections
List and review active SAML and OIDC connections for your customers.

### Monitor directory syncs
Check the status of HRIS and SCIM directory instances from providers like Okta.

### Pull user rosters
Retrieve full lists of users and groups synced from external directories.

### Stream audit logs
Get real-time security and compliance events for any organization.

### Look up tenant IDs
Quickly find the unique IDs needed for enterprise feature configuration.

### Verify connection health
Check the status and metadata of active SSO and directory links.

## Use Cases

### Troubleshooting a broken login
An engineer asks the agent to check the status of an OIDC connection for a specific company. The agent uses `get_sso_connection_details` to confirm it's active and reports back.

### Security audit
A compliance officer asks for all audit logs from the last hour for a specific organization. The agent uses `get_audit_log_events` to stream the data.

### Onboarding a new client
A product manager needs to create a new organization with five specific domains. The agent uses `create_workos_organization` to handle the setup.

### Sync verification
A support agent wants to know if the Okta directory is still syncing. The agent uses `list_directories` and `get_directory_details` to verify the status.

## Benefits

- Stop hunting for IDs: Use `list_workos_organizations` to find the exact tenant data you need without manual searching.
- Faster troubleshooting: Use `get_sso_connection_details` to see if a SAML link is healthy in one step.
- Instant audit access: Use `get_audit_log_events` to stream security logs directly into your chat.
- Real-time sync monitoring: Use `list_directories` to see the actual status of your HRIS and SCIM instances.
- Rapid user lookups: Use `list_directory_users` to get a full roster of synced accounts instantly.
- Streamlined onboarding: Use `create_workos_organization` to set up new enterprise records with authorized domains.

## How It Works

The bottom line is you get an identity admin that works through a chat interface.

1. Subscribe to the WorkOS MCP and grab your API key.
2. Connect the Connector to your preferred AI client like Claude or Cursor.
3. Ask your agent to perform actions like listing organizations or checking sync statuses.

## Frequently Asked Questions

**What does the WorkOS MCP do for my AI agent?**
It connects your AI agent to your WorkOS account so you can manage organizations, SSO connections, and directory syncs using natural language commands.

**Can I use the WorkOS MCP to manage SAML and OIDC connections?**
Yes. You can use your agent to list all active connections, check their current health status, and retrieve specific metadata for any SSO link.

**Does the WorkOS MCP support Okta and Azure AD directory syncs?**
Yes. It allows your agent to monitor active sync instances and pull deep details on the status of your HRIS and SCIM directory connections.

**Can I use WorkOS MCP to check security audit logs?**
Yes. Your agent can stream audit log events for any organization to help you monitor security activities and maintain compliance.

**Is the WorkOS MCP good for support teams?**
It is excellent for support. It lets your team quickly look up organization details and user rosters to provide faster technical assistance to customers.

**How does the WorkOS MCP help with enterprise onboarding?**
It allows your agent to create new organization records and manage authorized domains, making it much faster to set up new enterprise tenants.

**Can I check the sync status of a specific company directory through the agent?**
Yes. The `get_directory_details` tool allows your AI agent to retrieve the current sync status and metadata for any specific directory ID, helping you monitor whether employees are being correctly provisioned.

**How do I see which users belong to a specific synced group?**
You can use the `list_directory_users` tool and filter by the directory ID to see the full roster. For group-level information, use the `list_directory_groups` tool to see organizational units imported from the identity provider.

**Is it possible to retrieve security audit logs via chat?**
Absolutely. The `get_audit_log_events` tool retrieves a stream of events for any specific organization ID, giving you instant access to compliance-related activities directly through your conversation.