ClaudeChatGPTPerplexityGeminiMicrosoft CopilotRaycastMeta AIGrokZ.aiQwenKimi
DeepSeekMistralCursorVS CodeWindsurfJetBrainsClineLovableVercel AI SDKLangChain

Use CyberArk with your AI.

Connect your account once and let the AI you already use work with it, without building another integration. Manage privileged access via CyberArk. audit secure safes, checkout vaulted account passwords, monitor users, and terminate sessions directly from any AI agent

Included with plan

Ask AI about this Connector

Developed, maintained, and hosted by Vinkius.

MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED

Waiting for input…

Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.

ChatGPTClaudeCursorPerplexityGeminiMicrosoft CopilotRaycastMeta AI

Complete set · 10 capabilities

The complete CyberArk capability set.

These are the exact actions your AI can choose when you ask it to work with CyberArk.

Capability set01 / 03

01-04

4 capabilities in this set.

Part of 10 available through CyberArk.

  1. 01

    Delete account

    Requires high authorization. Used during system decommissioning so the CPM stops attempting failed password rotations. Delete a privileged account from the CyberArk Vault

  2. 02

    Get account

    Necessary before rotating or interacting with an account. Get detailed properties for a specific vaulted account

  3. 03

    List accounts

    These represent highly sensitive credentials (Root, Administrator, Service Accounts). Includes the bounding platform, Safe allocation, address, and rotational status. Use the search string to narrow targets. Search and list privileged accounts vaulted in CyberArk

  4. 04

    List safes

    Safes are the fundamental logical containers separating credentials physically and logically. Required to locate where specific critical tier-0 credentials or local admin passwords reside. List all secure Safes in CyberArk Privileged Access Manager

Capability set02 / 03

05-07

3 capabilities in this set.

Part of 10 available through CyberArk.

  1. 05

    Retrieve password

    Highly audited endpoint triggering SIEM alerts. A justification reason is mandatory. After retrieval, exclusive access platforms may lock the credential until check-in or auto-rotation. Retrieve the clear-text password for an account (check-out)

  2. 06

    Get safe

    Get details and metadata for a specific PAM Safe

  3. 07

    List groups

    Permissions to Safes are canonically granted to Groups rather than individual users to enforce RBAC best practices. Used to verify PAM logical access architectures. List CyberArk Vault User Groups

Capability set03 / 03

08-10

3 capabilities in this set.

Part of 10 available through CyberArk.

  1. 08

    List users

    Identifies active vault administrators, auditors, and human end-users consuming PSM (Privileged Session Manager) sessions. List all CyberArk users (local and synchronized)

  2. 09

    Terminate session

    Used as an active incident response mechanism if a SOC analyst or anomalous behavior engine detects unauthorized actions mid-session. Forcibly terminate an active Privileged Session (PSM/PSMP)

  3. 10

    Add account

    Requires precise mapping to an underlying Platform ID (e.g., WinDesktopLocal, UnixSSH) which dictates how CyberArk rotates and verifies the credential moving forward. Provision a new privileged account into a Vault Safe

Observed, not estimated

860ms average. Fast in production.

CyberArk is checked daily against the live service.

Daily averagePeak 1010ms
Aug 20Today
Fastest day
703ms
Slowest day
1010ms
14-day trend
Slowing+13%

Connect your client

One URL. Every client.

Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.

Preview access · not provider authentication

The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of CyberArk, so you can see the experience inside your AI.

It does not authenticate your account with CyberArk. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.

CyberArk Connector

You're all set. Choose your MCP client and follow the setup instructions.

Connector linkhttps://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp

Claude Desktop

Follow the steps below to connect in seconds.

  1. 1In Claude Desktop, open Settings → Connectors.
  2. 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
  3. 3Click Add and start a new chat — CyberArk capabilities are ready to use.
Configuration · claude_desktop_config.jsonCopy
{
  "mcpServers": {
    "cyberark-privilege-cloud-mcp": {
      "url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
    }
  }
}
  • Claude
  • ChatGPT
  • Cursor
  • VS Code
  • Windsurf
  • Claude Code
  • JetBrains
  • Cline

Step-by-step instructions for each client are in the guide. How to connect

FAQ

Questions CyberArk owners ask.

  • 01

    Can my agent retrieve a privileged password for an emergency maintenance task?

    Yes. Use the 'retrieve_password' capability. You must provide the account ID and a justification reason. The agent pulls the secret from the Vault, and the action is fully audited in CyberArk's system logs for compliance.

  • 02

    How do I terminate a suspicious active session via the agent?

    Provide the session ID to the 'terminate_session' capability. The agent will dispatch an instant interrupt signal to the CyberArk platform, killing the live SSH or RDP session immediately to prevent unauthorized actions.

  • 03

    Is it possible to add new service accounts to a Safe through chat?

    Absolutely. Use the 'add_account' capability. You'll need to specify the account name, address, username, platform ID, and the destination Safe. Your agent will onboard the credential and link it to the CPM for automated rotation.