2,500+ MCP servers ready to use
Vinkius

CyberArk Privilege Cloud MCP Server for Windsurf 10 tools — connect in under 2 minutes

Built by Vinkius GDPR 10 Tools IDE

Windsurf brings agentic AI coding to a purpose-built IDE. Connect CyberArk Privilege Cloud through the Vinkius and Cascade will auto-discover every tool — ask questions, generate code, and act on live data without leaving your editor.

Vinkius supports streamable HTTP and SSE.

RecommendedModern Approach — Zero Configuration

Vinkius Desktop App

The modern way to manage MCP Servers — no config files, no terminal commands. Install CyberArk Privilege Cloud and 2,500+ MCP Servers from a single visual interface.

Vinkius Desktop InterfaceVinkius Desktop InterfaceVinkius Desktop InterfaceVinkius Desktop Interface
Download Free Open SourceNo signup required
Classic Setup·json
{
  "mcpServers": {
    "cyberark-privilege-cloud": {
      "url": "https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp"
    }
  }
}
CyberArk Privilege Cloud
Fully ManagedVinkius Servers
60%Token savings
High SecurityEnterprise-grade
IAMAccess control
EU AI ActCompliant
DLPData protection
V8 IsolateSandboxed
Ed25519Audit chain
<40msKill switch
Stream every event to Splunk, Datadog, or your own webhook in real-time

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure

About CyberArk Privilege Cloud MCP Server

Connect your CyberArk Privilege Cloud account to any AI agent and take full control of your identity security and privileged access management through natural conversation.

Windsurf's Cascade agent chains multiple CyberArk Privilege Cloud tool calls autonomously — query data, analyze results, and generate code in a single agentic session. Paste the Vinkius Edge URL, reload, and all 10 tools are immediately available. Real-time tool feedback appears inline, so you see API responses directly in your editor.

What you can do

  • Safe Orchestration — List secure Safes and retrieve intricate settings including retention periods and assigned Central Policy Managers (CPM)
  • Privileged Account Management — Enumerate vaulted credentials (Root, Administrator, Service Accounts) and audit rotational statuses and address mappings
  • Password Retrieval (Check-out) — Pull actual secrets from the Vault with mandatory audited justifications, allowing the agent to securely retrieve credentials for incident response
  • Identity Oversight — List internal and LDAP-mapped directory users and groups to verify PAM logical access architectures and RBAC rules
  • Session Control — Forcibly terminate active PSM/PSMP privileged sessions instantly as an active incident response mechanism
  • Vault Onboarding — Provision new privileged accounts into secure Safes by mapping them to specific platform IDs for automated rotation lifecycle management

The CyberArk Privilege Cloud MCP Server exposes 10 tools through the Vinkius. Connect it to Windsurf in under two minutes — no API keys to rotate, no infrastructure to provision, no vendor lock-in. Your configuration, your data, your control.

How to Connect CyberArk Privilege Cloud to Windsurf via MCP

Follow these steps to integrate the CyberArk Privilege Cloud MCP Server with Windsurf.

01

Open MCP Settings

Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"

02

Add the server

Paste the JSON configuration above into mcp_config.json

03

Save and reload

Windsurf will detect the new server automatically

04

Start using CyberArk Privilege Cloud

Open Cascade and ask: "Using CyberArk Privilege Cloud, help me..."10 tools available

Why Use Windsurf with the CyberArk Privilege Cloud MCP Server

Windsurf provides unique advantages when paired with CyberArk Privilege Cloud through the Model Context Protocol.

01

Windsurf's Cascade agent autonomously chains multiple tool calls in sequence, solving complex multi-step tasks without manual intervention

02

Purpose-built for agentic workflows — Cascade understands context across your entire codebase and integrates MCP tools natively

03

JSON-based configuration means zero code changes: paste a URL, reload, and all 10 tools are immediately available

04

Real-time tool feedback is displayed inline, so you see API responses directly in your editor without switching contexts

CyberArk Privilege Cloud + Windsurf Use Cases

Practical scenarios where Windsurf combined with the CyberArk Privilege Cloud MCP Server delivers measurable value.

01

Automated code generation: ask Cascade to fetch data from CyberArk Privilege Cloud and generate models, types, or handlers based on real API responses

02

Live debugging: query CyberArk Privilege Cloud tools mid-session to inspect production data while debugging without leaving the editor

03

Documentation generation: pull schema information from CyberArk Privilege Cloud and have Cascade generate comprehensive API docs automatically

04

Rapid prototyping: combine CyberArk Privilege Cloud data with Cascade's code generation to scaffold entire features in minutes

CyberArk Privilege Cloud MCP Tools for Windsurf (10)

These 10 tools become available when you connect CyberArk Privilege Cloud to Windsurf via MCP:

01

add_account

Requires precise mapping to an underlying Platform ID (e.g., WinDesktopLocal, UnixSSH) which dictates how CyberArk rotates and verifies the credential moving forward. Provision a new privileged account into a Vault Safe

02

delete_account

Requires high authorization. Used during system decommissioning so the CPM stops attempting failed password rotations. Delete a privileged account from the CyberArk Vault

03

get_account

Necessary before rotating or interacting with an account. Get detailed properties for a specific vaulted account

04

get_safe

Get details and metadata for a specific PAM Safe

05

list_accounts

These represent highly sensitive credentials (Root, Administrator, Service Accounts). Includes the bounding platform, Safe allocation, address, and rotational status. Use the search string to narrow targets. Search and list privileged accounts vaulted in CyberArk

06

list_groups

Permissions to Safes are canonically granted to Groups rather than individual users to enforce RBAC best practices. Used to verify PAM logical access architectures. List CyberArk Vault User Groups

07

list_safes

Safes are the fundamental logical containers separating credentials physically and logically. Required to locate where specific critical tier-0 credentials or local admin passwords reside. List all secure Safes in CyberArk Privileged Access Manager

08

list_users

Identifies active vault administrators, auditors, and human end-users consuming PSM (Privileged Session Manager) sessions. List all CyberArk users (local and synchronized)

09

retrieve_password

Highly audited endpoint triggering SIEM alerts. A justification reason is mandatory. After retrieval, exclusive access platforms may lock the credential until check-in or auto-rotation. Retrieve the clear-text password for an account (check-out)

10

terminate_session

Used as an active incident response mechanism if a SOC analyst or anomalous behavior engine detects unauthorized actions mid-session. Forcibly terminate an active Privileged Session (PSM/PSMP)

Example Prompts for CyberArk Privilege Cloud in Windsurf

Ready-to-use prompts you can give your Windsurf agent to start working with CyberArk Privilege Cloud immediately.

01

"List all privileged accounts for address '10.0.0.1'"

02

"Retrieve password for account 123. Reason: 'Emergency DB maintenance'"

03

"Terminate active session 'sess_abc'"

Troubleshooting CyberArk Privilege Cloud MCP Server with Windsurf

Common issues when connecting CyberArk Privilege Cloud to Windsurf through the Vinkius, and how to resolve them.

01

Server not connecting

Check Settings → MCP for the server status. Try toggling it off and on.

CyberArk Privilege Cloud + Windsurf FAQ

Common questions about integrating CyberArk Privilege Cloud MCP Server with Windsurf.

01

How does Windsurf discover MCP tools?

Windsurf reads the mcp_config.json file on startup and connects to each configured server via Streamable HTTP. Tools are listed in the MCP panel and available to Cascade automatically.
02

Can Cascade chain multiple MCP tool calls?

Yes. Cascade is an agentic system — it can plan and execute multi-step workflows, calling several tools in sequence to accomplish complex tasks without manual prompting between steps.
03

Does Windsurf support multiple MCP servers?

Yes. Add as many servers as needed in mcp_config.json. Each server's tools appear in the MCP panel and Cascade can use tools from different servers in a single flow.

Connect CyberArk Privilege Cloud to Windsurf

Get your token, paste the configuration, and start using 10 tools in under 2 minutes. No API key management needed.