Compatible with every major AI agent and IDE
What is the BoxyHQ (Enterprise SSO) MCP Server?
Connect your BoxyHQ instance to any AI agent to streamline enterprise authentication and user lifecycle management through natural language.
What you can do
- SSO Connections — Add, update, and manage SAML and OIDC connections for specific tenants and products.
- Directory Sync (SCIM) — Create and configure SCIM 2.0 directories to automate user provisioning and de-provisioning.
- Connection Auditing — Retrieve detailed connection metadata using tenant IDs, product IDs, or client IDs.
- Metadata Management — Configure IdP metadata via raw XML (Base64) or direct metadata URLs for rapid deployment.
- Lifecycle Control — Update existing security configurations or delete stale connections to maintain a clean security posture.
How it works
- Subscribe to this server
- Enter your BoxyHQ Instance URL and API Key
- Start managing enterprise identity workflows from Claude, Cursor, or any MCP-compatible client
Who is this for?
- Security Engineers — quickly audit and update SSO configurations across multiple tenants without manual dashboard navigation.
- DevOps & SREs — automate the creation of SCIM directories and SAML connections during customer onboarding.
- Product Managers — verify the status of enterprise integrations and connection health directly from the chat interface.
Built-in capabilities (8)
Add a new SAML or OIDC connection
0 protocol. Create a Directory Sync (SCIM) connection
Delete an SSO connection
Get SSO connections
List all groups for a tenant/product directory
List all users for a tenant/product directory
Check BoxyHQ service health
Update an existing SSO connection
Why Claude Code?
Claude Code registers BoxyHQ (Enterprise SSO) as an MCP server in a single terminal command. Once connected, Claude Code discovers all 8 tools at runtime and can call them headlessly. ideal for CI/CD pipelines, cron jobs, and automated workflows where BoxyHQ (Enterprise SSO) data drives decisions without human intervention.
- —
Single-command setup:
claude mcp addregisters the server instantly. no config files to edit or applications to restart - —
Terminal-native workflow means MCP tools integrate seamlessly into shell scripts, CI/CD pipelines, and automated DevOps tasks
- —
Claude Code runs headlessly, enabling unattended batch processing using BoxyHQ (Enterprise SSO) tools in cron jobs or deployment scripts
- —
Built by the same team that created the MCP protocol, ensuring first-class compatibility and the fastest adoption of new protocol features
BoxyHQ (Enterprise SSO) in Claude Code
BoxyHQ (Enterprise SSO) and 4,000+ other MCP servers. One platform. One governance layer.
Teams that connect BoxyHQ (Enterprise SSO) to Claude Code through Vinkius don't need to source, host, or maintain individual MCP servers. Every tool call runs inside a hardened runtime with credential isolation, DLP, and a signed audit chain.
Raw MCP | Vinkius | |
|---|---|---|
| Server catalog | Find and host yourself | 4,000+ managed |
| Infrastructure | Self-hosted | Sandboxed V8 isolates |
| Credential handling | Plaintext in config | Vault + runtime injection |
| Data loss prevention | None | Configurable DLP policies |
| Kill switch | None | Global instant shutdown |
| Financial circuit breakers | None | Per-server limits + alerts |
| Audit trail | None | Ed25519 signed logs |
| SIEM log streaming | None | Splunk, Datadog, Webhook |
| Honeytokens | None | Canary alerts on leak |
| Custom domains | Not applicable | DNS challenge verified |
| GDPR compliance | Manual effort | Automated purge + export |
Why teams choose Vinkius for BoxyHQ (Enterprise SSO) in Claude Code
The BoxyHQ (Enterprise SSO) MCP Server runs on Vinkius-managed infrastructure inside AWS — a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts. All 8 tools execute in hardened sandboxes optimized for native MCP execution.
Your AI agents in Claude Code only access the data you authorize, with DLP that blocks sensitive information from ever reaching the model, kill switch for instant shutdown, and up to 60% token savings. Enterprise-grade infrastructure, zero maintenance.

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure
How Vinkius secures
BoxyHQ (Enterprise SSO) for Claude Code
Every tool call from Claude Code to the BoxyHQ (Enterprise SSO) MCP Server is protected by DLP redaction, cryptographic audit chains, V8 sandbox isolation, kill switch, and financial circuit breakers.
Frequently asked questions
Can I configure a SAML connection using just the metadata URL?
Yes! Use the add_connection tool and provide the metadataUrl. The server will fetch and process the IdP configuration automatically.
How do I find the clientID for an existing connection?
You can use the get_connections tool by providing the tenant and product IDs. It will return all matching connections including their unique clientIDs.
Does this support SCIM for automated user provisioning?
Absolutely. Use the create_directory tool to set up a SCIM 2.0 directory for providers like Okta, Azure AD, or Google, including webhook support for events.
How do I add an MCP server to Claude Code?
Run claude mcp add <name> --transport http "<url>" in your terminal. Claude Code registers the server and discovers all tools immediately.
Can Claude Code run MCP tools in headless mode?
Yes. Claude Code supports non-interactive execution, making it ideal for scripts, cron jobs, and CI/CD pipelines that need MCP tool access.
How do I list all connected MCP servers?
Run claude mcp in your terminal to see all registered servers and their status, or type /mcp inside an active Claude Code session.
Command not found: claude
Ensure Claude Code is installed globally: npm install -g @anthropic-ai/claude-code
Connection timeout
Check your internet connection and verify the Edge URL is reachable
Explore More MCP Servers
View all →
tl;dv
12 toolsRecord, transcribe, and clip key moments from Google Meet and Zoom calls so your team never misses important meeting insights.

Lexzur
10 toolsManage legal operations with contract lifecycle tracking, matter management, and compliance workflows for corporate legal teams.

DoiT
10 toolsEquip your AI agent to manage cloud costs, track assets across AWS/GCP/Azure, and monitor cost anomalies via the DoiT API.

PhantomBuster
10 toolsAutomate web data extraction via PhantomBuster — list Phantoms, launch automations, and track results directly from any AI agent.
