Use CyberArk with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Manage privileged access via CyberArk. audit secure safes, checkout vaulted account passwords, monitor users, and terminate sessions directly from any AI agent
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 10 capabilities
The complete CyberArk capability set.
These are the exact actions your AI can choose when you ask it to work with CyberArk.
01-04
4 capabilities in this set.
Part of 10 available through CyberArk.
- 01
Delete account
Requires high authorization. Used during system decommissioning so the CPM stops attempting failed password rotations. Delete a privileged account from the CyberArk Vault
- 02
Get account
Necessary before rotating or interacting with an account. Get detailed properties for a specific vaulted account
- 03
List accounts
These represent highly sensitive credentials (Root, Administrator, Service Accounts). Includes the bounding platform, Safe allocation, address, and rotational status. Use the search string to narrow targets. Search and list privileged accounts vaulted in CyberArk
- 04
List safes
Safes are the fundamental logical containers separating credentials physically and logically. Required to locate where specific critical tier-0 credentials or local admin passwords reside. List all secure Safes in CyberArk Privileged Access Manager
05-07
3 capabilities in this set.
Part of 10 available through CyberArk.
- 05
Retrieve password
Highly audited endpoint triggering SIEM alerts. A justification reason is mandatory. After retrieval, exclusive access platforms may lock the credential until check-in or auto-rotation. Retrieve the clear-text password for an account (check-out)
- 06
Get safe
Get details and metadata for a specific PAM Safe
- 07
List groups
Permissions to Safes are canonically granted to Groups rather than individual users to enforce RBAC best practices. Used to verify PAM logical access architectures. List CyberArk Vault User Groups
08-10
3 capabilities in this set.
Part of 10 available through CyberArk.
- 08
List users
Identifies active vault administrators, auditors, and human end-users consuming PSM (Privileged Session Manager) sessions. List all CyberArk users (local and synchronized)
- 09
Terminate session
Used as an active incident response mechanism if a SOC analyst or anomalous behavior engine detects unauthorized actions mid-session. Forcibly terminate an active Privileged Session (PSM/PSMP)
- 10
Add account
Requires precise mapping to an underlying Platform ID (e.g., WinDesktopLocal, UnixSSH) which dictates how CyberArk rotates and verifies the credential moving forward. Provision a new privileged account into a Vault Safe
Observed, not estimated
860ms average. Fast in production.
CyberArk is checked daily against the live service.
- Fastest day
- 703ms
- Slowest day
- 1010ms
- 14-day trend
- Slowing+13%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of CyberArk, so you can see the experience inside your AI.
It does not authenticate your account with CyberArk. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
CyberArk Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — CyberArk capabilities are ready to use.
{
"mcpServers": {
"cyberark-privilege-cloud-mcp": {
"url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions CyberArk owners ask.
- 01
Can my agent retrieve a privileged password for an emergency maintenance task?
Yes. Use the 'retrieve_password' capability. You must provide the account ID and a justification reason. The agent pulls the secret from the Vault, and the action is fully audited in CyberArk's system logs for compliance.
- 02
How do I terminate a suspicious active session via the agent?
Provide the session ID to the 'terminate_session' capability. The agent will dispatch an instant interrupt signal to the CyberArk platform, killing the live SSH or RDP session immediately to prevent unauthorized actions.
- 03
Is it possible to add new service accounts to a Safe through chat?
Absolutely. Use the 'add_account' capability. You'll need to specify the account name, address, username, platform ID, and the destination Safe. Your agent will onboard the credential and link it to the CPM for automated rotation.
Explore
More in Fort Knox
Sirv AI Connector
Enable your AI agent to manage files, read metadata, and monitor bandwidth usage on your Sirv CDN account.
ViewPagerDuty AI Connector
Manage incidents, services, on-call schedules, and escalation policies via PagerDuty — trigger, acknowledge, a
ViewCrowdStrike Falcon AI Connector
Detect threats, manage endpoints, investigate incidents, and query telemetry from CrowdStrike Falcon — the #1
ViewEverbridge Critical Management AI Connector
Equip your AI agent to manage critical notifications, track incidents, and monitor contacts via the Everbridge
View
Suggestions
Cyberimpact AI Connector
Email marketing automation with Cyberimpact.
ViewCyberimpact AI Connector
Manage email marketing lists and members — list subscribers, update profiles, and organize groups directly fro
ViewYodlee AI Connector
Access financial data via Yodlee — list accounts, fetch transactions, and verify banking details directly from
ViewCortex XSIAM AI Connector
Connect Cortex XSIAM to any AI agent via MCP.
View
