CyberArk Privilege Cloud Connector for AI agents.
10 live capabilities
Manage privileged access and vaulted credentials with conversational commands.
Waiting for input…
Why people use CyberArk Privilege Cloud
CyberArk Privilege Cloud for Faster Privileged Access Management
This Connector changes the game by letting you handle these tasks through a chat interface. You can check account statuses, pull secrets, or kill sessions with a single sentence, turning a multi-step manual process into a few seconds of work.
What Vinkius changes
You get direct, conversational control over your CyberArk vault without leaving your primary workspace.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Stopping a breach
A SOC analyst sees an active session on a production database and tells their agent to use terminate_session to kill it.
- Real-world use case 02
Emergency maintenance
A DevOps engineer asks the agent to retrieve_password for a specific server to perform a midnight update.
- Real-world use case 03
Compliance check
An auditor asks the agent to list_groups for a specific safe to ensure only the right people have access.
Complete set · 10capabilities
The complete CyberArk Privilege Cloud capability set.
These are the exact actions your AI can choose when you ask it to work with CyberArk Privilege Cloud.
01—04
4 capabilities in this set.
Part of 10 available through CyberArk Privilege Cloud.
- 01 Capability
Delete account
Remove a privileged account from the vault to stop failed password rotations during a system decommissioning.
- 02 Capability
Get account
Get the full property list for a specific vaulted account before you rotate or interact with it.
- 03 Capability
Get safe
Get the metadata and configuration details for a specific PAM safe.
- 04 Capability
List accounts
Search and list sensitive credentials like Root or Admin accounts across your vault.
05—07
3 capabilities in this set.
Part of 10 available through CyberArk Privilege Cloud.
- 05 Capability
List groups
List the user groups that have permissions to specific safes to verify RBAC rules.
- 06 Capability
List safes
List all secure containers in CyberArk to find where your most sensitive tier-0 credentials live.
- 07 Capability
List users
Identify all local and synchronized users, including vault admins and auditors.
08—10
3 capabilities in this set.
Part of 10 available through CyberArk Privilege Cloud.
- 08 Capability
Retrieve password
Retrieve the clear-text password for an account after providing a mandatory justification.
- 09 Capability
Terminate session
Forcibly end an active PSM or PSMP session to stop unauthorized actions immediately.
- 10 Capability
Add account
Provision a new privileged account into a vault safe with the specific Platform ID required for rotation.
Set up in minutes
One URL. Then ask CyberArk Privilege Cloud to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use CyberArk Privilege Cloud from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it CyberArk Privilege Cloud, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable CyberArk Privilege Cloud for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the CyberArk Privilege Cloud URL.
- Step 03
Save and start
Save the connection and enable CyberArk Privilege Cloud in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"cyberark-privilege-cloud": {
"url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using CyberArk Privilege Cloud
Open Agent mode in chat and ask: "Using CyberArk Privilege Cloud, help me...". 10 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"cyberark-privilege-cloud": {
"url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using CyberArk Privilege Cloud
Ask Copilot: "Using CyberArk Privilege Cloud, help me...". 10 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"cyberark-privilege-cloud": {
"url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using CyberArk Privilege Cloud
Open Cascade and ask: "Using CyberArk Privilege Cloud, help me...". 10 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"cyberark-privilege-cloud": {
"url": "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using CyberArk Privilege Cloud
Ask Cline: "Using CyberArk Privilege Cloud, help me...". 10 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add cyberark-privilege-cloud --transport http "https://edge.vinkius.com/vk_preview_18gJHbsKGjtg9GOn25i2jhe0oFuy772lTZzUa9w1/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using CyberArk Privilege Cloud
Ask Claude: "Using CyberArk Privilege Cloud, show me...". 10 tools are ready
Where the request belongs
Work CyberArk can move forward.
This is for the security pro who's tired of the portal fatigue that comes with managing thousands of privileged accounts. It's for the analyst who needs to move fast during a breach and the admin who hates manual data entry.
SOC Analyst
Investigates alerts and kills suspicious sessions in real-time.
IT Administrator
Onboards service accounts and configures safes without the PVWA UI.
Compliance Auditor
Pulls user lists and group memberships to verify security policies.
DevOps Engineer
Grabs temporary credentials for maintenance tasks with full audit trails.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsHudu
Document your IT infrastructure with password vaults, knowledge bases, and asset tracking built for managed service providers.
Authing
Cloud-native identity and access management platform. manage users, roles, and security logs via AI.
HashiCorp Vault
Securely manage secrets, tokens, and encryption keys via HashiCorp Vault. read KV secrets, generate dynamic credentials, and monitor system health.
Vanta
Manage your automated compliance and security posture. Audit users, devices, vendors, and vulnerabilities directly from your AI agent.
Infisical
Manage secrets infrastructure via AI. list, create, update, and audit secrets across environments with end-to-end encryption.
NetBird
Automate Zero Trust networking via NetBird. manage accounts, users, and access controls directly from any AI agent.
Bring your own AI
Change the model, client or framework. Keep CyberArk connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about CyberArk.
The practical details behind the request, access and result.
Can the CyberArk Privilege Cloud MCP help me during a security incident?
Yes, it allows you to kill active sessions instantly. If you spot unauthorized behavior, your agent can terminate the session in seconds to stop the threat.
How does the CyberArk Privilege Cloud MCP handle password retrieval?
It pulls clear-text secrets for you but requires a mandatory justification. This ensures that every time a secret is accessed, there is a clear audit trail for your security team.
Can I use the CyberArk Privilege Cloud MCP to see who has access to my safes?
Yes, you can list the users and groups associated with your safes. This makes it easy to verify that your RBAC rules are being followed correctly.
Does the CyberArk Privilege Cloud MCP support automated account onboarding?
Yes, you can use it to provision new privileged accounts into your vault. It handles the mapping to specific platform IDs so rotation starts immediately.
Can I use the CyberArk Privilege Cloud MCP to audit my vault configuration?
Yes, you can list all your safes and get detailed metadata. This helps you get a clear picture of your vault's structure and security settings without manual searching.
Is the CyberArk Privilege Cloud MCP safe for production use?
Yes, it works with your existing CyberArk credentials and logs every single action. It provides a secure, audited way to interact with your vault through your AI client.
Can my agent retrieve a privileged password for an emergency maintenance task?
Yes. Use the 'retrieve_password' capability. You must provide the account ID and a justification reason. The agent pulls the secret from the Vault, and the action is fully audited in CyberArk's system logs for compliance.
How do I terminate a suspicious active session via the agent?
Provide the session ID to the 'terminate_session' capability. The agent will dispatch an instant interrupt signal to the CyberArk platform, killing the live SSH or RDP session immediately to prevent unauthorized actions.
Is it possible to add new service accounts to a Safe through chat?
Absolutely. Use the 'add_account' capability. You'll need to specify the account name, address, username, platform ID, and the destination Safe. Your agent will onboard the credential and link it to the CPM for automated rotation.
One connection away
Give your agent a direct line to CyberArk.
Connect CyberArk once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available