Skip to content

Integration · Developer tools

Connect Claude & ChatGPT to Coro

Ask your AI which security tickets are still open, what happened on a device, or who is protected in your Coro workspace. It can read tickets and their available actions, summarize tickets for devices, users, email, cloud apps and data, search the activity log and check your subscription and usage. It can also add users to protection or switch protection on and off, with your approval if you want it.

Connect Coro free

Free plan, no credit card. Takes about a minute.

Try asking

  • “Which security tickets from the last 7 days are still unprocessed?”

    The AI lists tickets with processed set to false in that time range, with trigger and affected user or device.

  • “Give me an overview of email threats since the start of the month.”

    It summarizes email security findings such as phishing and malware, with their related tickets.

  • “What can I do about ticket 88412?”

    It reads the ticket and lists the actions available for it, for example ways to resolve it.

What your AI can do

Tickets and summaries

List and read security tickets, see the actions available for each, and get summaries for devices, users, email, cloud apps and data governance.

Users and devices

List protected users and devices, add users to protection, switch protection on or off and remove a protected user.

Workspace and audit

Read workspace details, subscription modules, usage, admin portal users and the activity log.

  • “Add [email protected] and [email protected] to protection.”

    It adds both users as protected users. Protected users may count toward your Coro subscription.

  • “Which actions can I run on the device with enrollment code 7G2K9?”

    It finds the device and lists the actions it supports, such as a malware scan or tamper protection.

  • “Who changed settings in the workspace last week?”

    It searches the activity log for that time range and lists the entries it finds.

20 tools for Coro

These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.

  • add_protected_usersChanges dataAdd up to 200 users to protection, passing `users` as a list of objects with `email` and optional `name`. Protected users may count toward your Coro subscription.
  • get_protected_userGet one protected user by `user_id`.
  • get_subscriptionGet the workspace's Coro subscription: bundles, modules and add-ons.
  • get_ticketGet one security ticket by `ticket_id`, with its trigger, affected user or device and status.
  • get_usageGet usage for the workspace between `start` and `end` (UNIX time in milliseconds). Paginated with `page` and `limit`.
  • get_workspaceGet the details of the connected Coro workspace, such as company name, type and limits.
  • list_device_actionsList the actions supported for one device by `enrollment_code`, such as a malware scan or tamper protection.
  • list_devicesList protected devices in the workspace, optionally filtered by `enrollment_code` (the device ID). Paginated with `page` and `limit`.
  • list_portal_usersList admin portal users, optionally filtered by `email`. Paginated with `page` and `limit`.
  • list_protected_usersList protected users, optionally filtered by `email` or `name`. Paginated with `page` and `limit`. Use this to find a user's ID.
  • list_ticket_actionsList the actions available for one ticket by `ticket_id` (for example ways to resolve or treat it).
  • list_ticketsList security tickets, optionally filtered by `ticket_ids`, `ticket_triggers`, `processed` (true or false), and a `from_time`/`to_time` range in milliseconds. Paginated with `page` and `limit`.
  • remove_protected_userDeletesRemove a protected user by `user_id`. This cannot be undone; the user is no longer protected.
  • search_audit_logsSearch the activity log by `types`, `sub_types`, `ticket_ids`, `remediation` and a `from_time`/`to_time` range in milliseconds. Use `cursor` from a previous result for the next page.
  • set_user_protectionVisible to othersTurn protection on or off for a user by `email` with `protected_user` true or false.
  • summarize_cloud_app_ticketsGet a summary of protected cloud apps and their tickets. Optional `resolved_from_time` (UNIX time in milliseconds) sets the start of the period.
  • summarize_data_ticketsGet a summary of data governance (sensitive data) findings and their tickets. Optional `resolved_from_time` (UNIX time in milliseconds) sets the start of the period.
  • summarize_device_ticketsGet a summary of protected devices and their tickets. Optional `resolved_from_time` (UNIX time in milliseconds) sets the start of the period.
  • summarize_email_ticketsGet a summary of email security (phishing, malware) and related tickets. Optional `resolved_from_time` (UNIX time in milliseconds) sets the start of the period.
  • summarize_user_ticketsGet a summary of protected users and their tickets. Optional `resolved_from_time` (UNIX time in milliseconds) sets the start of the period.

Set up in three steps

  1. 1

    Pick the app

    Create a free PipMCP account and choose Coro from the app list.

  2. 2

    Paste your key

    Enter your Coro API host for your data region (api.secure.coro.net for the US, api.secure-eu.coro.net for the EU, api.secure-ca.coro.net for Canada), a Client ID and Client Secret, and the ID of the workspace the calls should run in. In the Coro console go to Control Panel > Connectors > API Credentials and click Create API Key. The secret is shown only once.

  3. 3

    Add the link to your AI

    You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:

    1. Click your name, then Settings › Connectors › Add custom connector.
    2. Paste your link as the Remote MCP server URL.
    3. Switch it on from the + menu in a chat.

Questions

What can the AI do in Coro?

The AI can read security tickets, ticket actions, protected users, devices, device actions, admin portal users, the activity log, the workspace, its subscription and its usage. It can summarize tickets for devices, users, email, cloud apps and data. It can add users to protection, switch protection on or off for a user and remove a protected user.

Does the AI see my Coro client secret?

No. Your Coro credentials are encrypted at rest and never shown to the AI. After you save them, they are not shown again, not even to you. The AI only sees the results of the tools it calls.

Can I control what the AI is allowed to do?

Yes. You choose which tools are switched on, so you can start read-only. Removing a protected user cannot be undone, and switching protection off leaves a user unprotected. Both can require your approval before they run. Every tool call is logged.

Does it work with ChatGPT?

Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.

What does it cost?

PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own Coro account.

Which API host should I enter?

Use the host for the data region your Coro workspace is in: api.secure.coro.net for the US, api.secure-eu.coro.net for the EU or api.secure-ca.coro.net for Canada. Enter it without https://.

Let your AI work in Coro today.

Start free. Your key stays encrypted, and you decide what the AI may do.

Connect Coro free

PipMCP is not affiliated with Coro. Product names are trademarks of their owners.