{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-07-05","analysis_method":"capability_triage","category":"Web Connector","description":"The official WorkOS connector lets you manage your WorkOS workspace from Claude in plain language, backed by the same API that powers the WorkOS Dashboard .\n\nAsk Claude to look up an organization, aud","did":"ant-dir-workos","homepage_url":"https://workos.com/","icon":"https://orkos.com/favicon.ico","id":"ant.dir.workos","installs":12458,"last_scanned":"2026-07-05","license":"","long_description":"The official WorkOS connector lets you manage your WorkOS workspace from Claude in plain language, backed by the same API that powers the WorkOS Dashboard .\n\nAsk Claude to look up an organization, audit a user's memberships, check an SSO connection, inspect a Directory Sync (SCIM) setup, review roles and permissions, or make changes across 300+ operations spanning the WorkOS platform.\n\n**What you can do**\n- Query your data: organizations, users and memberships, SSO connections, Directory Sync directories and users, roles/permissions/groups (RBAC), audit logs and events, AuthKit applications, domains, webhooks, and more.\n- Take action: create and update organizations, manage users and memberships, configure connections, and run other administrative operations.\n- Discover what's available: Claude can list the supported operations and their inputs, then pick the right one for your request.\n\n**Built for enterprise trust**\n- Secure OAuth 2.0 authentication — Claude acts with your own WorkOS identity and permissions, never a shared API key, and only within a single environment.\n- Destructive and billing-sensitive actions require explicit confirmation before they run.\n- Admins can disable the connector or restrict it to read-only, and access is always scoped to what your role is allowed to do.\n\nWorkOS is the enterprise-identity platform trusted by leading AI and SaaS companies for SSO, Directory Sync, AuthKit user management, RBAC, FGA, Vault, and audit logging. This connector brings that control surface into Claude.\n","name":"WorkOS","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-workos&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"WorkOS","publisher_url":"https://workos.com/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"The connector can query sensitive identity and security data in WorkOS (users, orgs, SSO/SCIM directories, audit logs, roles/permissions), which may include PII and security configuration details.","risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"It can perform administrative mutations across the WorkOS platform (e.g., update organizations, manage memberships, configure connections), potentially impacting authentication and access behavior.","risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"With broad administrative operations available, the connector may be able to delete WorkOS resources (users, orgs, connections, directories, webhooks), causing irreversible loss or service disruption if misused.","risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"The connector can execute arbitrary API operations via a generic mutation mechanism, enabling powerful administrative actions that function like command execution against your identity infrastructure.","risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"OAuth-based access implies stored credentials/tokens to act on your behalf within a WorkOS environment, creating risk if tokens are over-scoped or compromised.","risk_type":"requires_persistent_credentials","severity":"medium","title":"Stores long-lived access tokens"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["deletes_data","modifies_data","reads_private_data","requires_persistent_credentials","runs_code"],"tools":[{"description":"Lists the supported WorkOS API operations and their required inputs for discovery and planning.","name":"list_operations"},{"description":"Executes state-changing WorkOS API operations such as creating, updating, or deleting resources in the workspace.","name":"mutate","risk":{"category":"destructive","level":"high","why":"A generic mutation endpoint can perform powerful admin actions including deletions or configuration changes that may be irreversible or security-impacting."}},{"description":"Runs read-only queries against WorkOS resources such as organizations, users, connections, directories, RBAC data, and audit logs.","name":"query"},{"description":"Returns the current authenticated WorkOS identity and context associated with the connector session.","name":"whoami"}],"tools_count":4,"type":"web_connector","url":"https://claude.ai/directory/d3b03e81-aeaa-42bf-9c52-5270d5273b2d","uuid":"d3b03e81-aeaa-42bf-9c52-5270d5273b2d","version":""},"query_key":"workos","schema_version":1,"status":"match"}
