Claude security directory
WorkOS
Published by WorkOS
High risk
The official WorkOS connector lets you manage your WorkOS workspace from Claude in plain language, backed by the same API that powers the WorkOS Dashboard . Ask Claude to look up an organization, audit a user's memberships, check an SSO connection, inspect a Directory Sync (SCIM) setup, review roles and permissions, or make changes across 300+ operations spanning the WorkOS platform. **What you can do** - Query your data: organizations, users and memberships, SSO connections, Directory Sync directories and users, roles/permissions/groups (RBAC), audit logs and events, AuthKit applications, domains, webhooks, and more. - Take action: create and update organizations, manage users and memberships, configure connections, and run other administrative operations. - Discover what's available: Claude can list the supported operations and their inputs, then pick the right one for your request. **Built for enterprise trust** - Secure OAuth 2.0 authentication — Claude acts with your own WorkOS identity and permissions, never a shared API key, and only within a single environment. - Destructive and billing-sensitive actions require explicit confirmation before they run. - Admins can disable the connector or restrict it to read-only, and access is always scoped to what your role is allowed to do. WorkOS is the enterprise-identity platform trusted by leading AI and SaaS companies for SSO, Directory Sync, AuthKit user management, RBAC, FGA, Vault, and audit logging. This connector brings that control surface into Claude.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can query sensitive identity and security data in WorkOS (users, orgs, SSO/SCIM directories, audit logs, roles/permissions), which may include PII and security configuration details.
- Can change or update your information: It can perform administrative mutations across the WorkOS platform (e.g., update organizations, manage memberships, configure connections), potentially impacting authentication and access behavior.
- Can permanently delete data: With broad administrative operations available, the connector may be able to delete WorkOS resources (users, orgs, connections, directories, webhooks), causing irreversible loss or service disruption if misused.
- Can run commands or queries on your behalf: The connector can execute arbitrary API operations via a generic mutation mechanism, enabling powerful administrative actions that function like command execution against your identity infrastructure.
- Stores long-lived access tokens: OAuth-based access implies stored credentials/tokens to act on your behalf within a WorkOS environment, creating risk if tokens are over-scoped or compromised.
Available capabilities
This add-on exposes 4 tools or capabilities.
- list_operations
- mutate
- query
- whoami
The interactive security report will load automatically.