Cerbos (Access Control) Connector for AI agents.
19 live capabilities
Manage RBAC and ABAC policies and audit access control for your security infrastructure.
Waiting for input…
Why people use Cerbos (Access Control)
Cerbos for Automated Access Control Auditing
With this Connector, you just ask your agent to show you the latest audit logs or verify a specific permission. You get immediate answers and a clear view of your security posture in a single chat window.
What Vinkius changes
You get a conversational interface for managing complex authorization without touching your source code.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Auditing for Compliance
A security engineer needs to prove that only admins can delete records.
- Real-world use case 02
Development Testing
A backend dev wants to know if a user can view a specific record.
- Real-world use case 03
Performance Monitoring
An ops lead wants to see the request volume.
Complete set · 19capabilities
The complete Cerbos (Access Control) capability set.
These are the exact actions your AI can choose when you ask it to work with Cerbos (Access Control).
01—04
4 capabilities in this set.
Part of 19 available through Cerbos (Access Control).
- 01 Capability
Get health
Check the current status of your Cerbos instance. Use this to ensure your policy decision point is online and ready.
- 02 Capability
Get metrics
Pull Prometheus metrics from your Cerbos setup. This is perfect for monitoring performance and request volume.
- 03 Capability
Get policy
Fetch the details of a specific policy using its ID. This lets you inspect the logic of a single authorization rule.
- 04 Capability
Get schema
Get a specific schema by ID
05—08
4 capabilities in this set.
Part of 19 available through Cerbos (Access Control).
- 05 Capability
Add policy
Create a new policy within your Cerbos instance. Use this to define new permissions for users or resources.
- 06 Capability
Get authzen config
Retrieve the configuration metadata for your AuthZEN setup. This helps you verify the underlying configuration details.
- 07 Capability
Add schema
Create or update a resource schema in your system. This defines the structure of the objects your policies protect.
- 08 Capability
Authzen evaluation
Perform a single access evaluation using the AuthZEN framework. This is used for specific, single-point permission checks.
09—12
4 capabilities in this set.
Part of 19 available through Cerbos (Access Control).
- 09 Capability
Authzen evaluations
Run a batch of AuthZEN access evaluations at once. This is useful for testing multiple permissions in a single request.
- 10 Capability
Check resources
Evaluate if a specific principal has the rights to perform actions on a set of resources. This helps you quickly verify permissions during a security review.
- 11 Capability
Delete policy
Remove a specific policy from your system by its unique ID. Use this to clean up old or deprecated authorization rules.
- 12 Capability
Disable policy
Turn off a policy without deleting it from the system. This is useful for temporary maintenance or troubleshooting.
13—16
4 capabilities in this set.
Part of 19 available through Cerbos (Access Control).
- 13 Capability
Enable policy
Reactivate a disabled policy to restore its effect on the system. You can quickly toggle permissions on or off as needed.
- 14 Capability
Get server info
Retrieve the version and build information for your Cerbos instance. Use this to verify that you are running the correct software version.
- 15 Capability
List audit logs
View a list of recent access logs from your system. This is your primary way to check who did what and when.
- 16 Capability
List policies
Get a full list of all active policies in your Cerbos instance. Use this to see the entire scope of your authorization rules.
17—19
3 capabilities in this set.
Part of 19 available through Cerbos (Access Control).
- 17 Capability
List schemas
List all resource schemas currently defined in your system. This helps you understand the structure of your authorized resources.
- 18 Capability
Plan resources
Generate an AST query plan for filtering resources based on auth logic. This allows you to see how your database queries will be modified by security rules.
- 19 Capability
Update policy
Modify an existing policy to change its permissions or scope. This lets you make surgical changes to your authorization logic.
Set up in minutes
One URL. Then ask Cerbos (Access Control) to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Cerbos (Access Control) from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it Cerbos (Access Control), and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable Cerbos (Access Control) for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the Cerbos (Access Control) URL.
- Step 03
Save and start
Save the connection and enable Cerbos (Access Control) in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"cerbos-access-control": {
"url": "https://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using Cerbos (Access Control)
Open Agent mode in chat and ask: "Using Cerbos (Access Control), help me...". 19 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"cerbos-access-control": {
"url": "https://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using Cerbos (Access Control)
Ask Copilot: "Using Cerbos (Access Control), help me...". 19 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"cerbos-access-control": {
"url": "https://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using Cerbos (Access Control)
Open Cascade and ask: "Using Cerbos (Access Control), help me...". 19 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"cerbos-access-control": {
"url": "https://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using Cerbos (Access Control)
Ask Cline: "Using Cerbos (Access Control), help me...". 19 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add cerbos-access-control --transport http "https://edge.vinkius.com/vk_preview_InOwgNCcuNoJDDtlbw3Rpbk72NQ9Y39enLJWWQOg/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using Cerbos (Access Control)
Ask Claude: "Using Cerbos (Access Control), show me...". 19 tools are ready
Where the request belongs
Work Cerbos can move forward.
The security engineer who needs to verify permissions across dozens of microservices without writing custom scripts. The backend dev who wants to see how a policy will affect their database queries before they deploy.
Security Engineer
Auditing existing policies and verifying permission logic to ensure there are no over-privileged accounts.
Backend Developer
Testing authorization scenarios and generating database filter plans during the development cycle.
Compliance Officer
Retrieving audit logs and policy definitions to prove the system meets organizational security standards.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsPermit.io
Orchestrate full-stack authorization, manage RBAC/ReBAC policies, and evaluate permissions in real-time via Permit.io.
Cerbos
Decouple authorization logic from your application. Evaluate permissions, generate query plans, and manage access control via AI.
OpenFGA (Fine-Grained Auth)
Manage fine-grained authorization with OpenFGA. create stores, define authorization models, and manage relationship tuples directly from your AI agent.
Permify
Manage fine-grained authorization and access control via Permify. write schemas, manage relation tuples, and perform real-time permission checks.
Aserto
Manage authorization policies and evaluate access control decisions via Aserto. run Rego queries, check user permissions, and audit decision logs.
Authing
Cloud-native identity and access management platform. manage users, roles, and security logs via AI.
Bring your own AI
Change the model, client or framework. Keep Cerbos connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about Cerbos.
The practical details behind the request, access and result.
What does the Cerbos MCP do for my security?
It gives you a conversational interface to manage your RBAC and ABAC policies. You can check permissions, audit logs, and manage your security rules in plain English.
Can I use Cerbos MCP to check permissions for my users?
Yes, you can ask your agent to verify if a specific user has the rights to perform actions on certain resources, and it will check your Cerbos instance for the answer.
How does Cerbos MCP help with database queries?
It can generate AST query plans. This shows you exactly how your database filters will be modified by your authorization logic before you run the query.
Can I manage my RBAC policies with Cerbos MCP?
Yes, you can list, add, update, and disable policies directly through your AI client without needing to manually edit JSON files or use a dashboard.
Does Cerbos MCP support audit logs?
Yes, you can retrieve and review your access logs in plain English to see who accessed what resources and whether those actions were allowed.
Can I see the health of my Cerbos instance?
Yes, you can ask your agent to check the health status and Prometheus metrics of your Cerbos instance to ensure everything is running correctly.
How do I set up Cerbos MCP for my team?
Once you subscribe to the Connector on Vinkius, you just need to provide your Cerbos PDP URL and any necessary admin credentials to connect it to your AI client.
Can I test if a specific user has access to a resource without writing code?
Yes. You can ask the agent to use the check_resources capability by providing the principal (user) details and the resource you want to check. The agent will return the allowed or denied status based on your Cerbos policies.
How do I view all the authorization policies currently loaded in my Cerbos server?
Simply ask the agent to 'list all policies'. It will invoke the list_policies capability (requires Admin credentials) and display the IDs of all active policies in your environment.
Can the AI help me generate filters for my database based on permissions?
Yes, by using the plan_resources capability. The agent will generate a query plan (AST) that describes the conditions under which a user is allowed to access resources, which you can then apply to your database queries.
One connection away
Give your agent a direct line to Cerbos.
Connect Cerbos once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available