Skip to content

Integration · Developer tools

Connect Claude & ChatGPT to SSOJet

Ask your AI which organizations a user belongs to, what roles they hold, or who a customer's directory has synced, and get the answer from your SSOJet application. It can search and manage users and tenants, add users to tenants, list roles and their permissions, and read directory-sync users and groups. It can also invite people and assign roles, with your approval if you want it.

Connect SSOJet free

Free plan, no credit card. Takes about a minute.

Try asking

  • “Which tenants does [email protected] belong to, and what roles does she have?”

    The AI finds the user by email, lists her tenants and reads her roles in each one.

  • “Create a tenant for Nordic Foods with the domain nordicfoods.dk.”

    It creates the tenant with its name and email domain, ready for users to be added.

  • “Invite [email protected] to Nordic Foods as an admin.”

    It finds the role ID, creates the invitation and can send the invitation email.

What your AI can do

Users

Search, create and update users, set them active or inactive, and see their tenants and roles.

Tenants and invitations

Create and update tenants with their domains, add users to tenants, and send, list and resend invitations.

Roles and directory sync

Read roles and their permissions, assign roles within a tenant, and list users and groups synced from a tenant's directory.

  • “Which invitations to the Acme tenant are still pending?”

    It lists the tenant's invitations with status pending, and can resend one if you ask.

  • “Which users and groups has Acme's directory synced?”

    It lists the tenant's directory-sync connections and the users and groups synced from the one you pick.

  • “Deactivate the user [email protected].”

    It finds the user and sets them as inactive. Deleting a user instead is permanent.

23 tools for SSOJet

These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.

  • add_users_to_tenantChanges dataAdd existing users to a tenant by `tenantid`, passing their IDs in `user_ids`.
  • assign_tenant_rolesDeletesAssign roles to a user within a tenant, by `tenantid`, `userid` and `role_ids`. This changes what the user can access.
  • create_tenantChanges dataCreate a tenant (customer organization) with a `name` and its email `domains`, plus optional display name, external ID and metadata.
  • create_userChanges dataCreate a new user with `email` and/or `phone`, `first_name`, `last_name` and optional metadata.
  • delete_userDeletesPermanently delete a user by `userid`. This cannot be undone.
  • get_roleGet one role by `role_id`, including its description and permissions.
  • get_tenantGet one tenant by `tenantid`, with its name, display name, domains and metadata.
  • get_tenant_member_rolesGet the roles a user holds within one tenant, by `tenantid` and `userid`.
  • get_userGet one user by `userid`, with email, phone, name, status and metadata.
  • invite_to_tenantChanges dataInvite someone to a tenant by `tenantid`: `invitee` email, `inviter`, `role_ids`, optional expiry. Sends an invitation email when `send_invitation_email` is true.
  • list_directory_groupsList the groups synced from a tenant's directory, by `tenantid` and `directory_id`.
  • list_directory_usersList the users synced from a tenant's directory, by `tenantid` and `directory_id`.
  • list_rolesList the roles defined for your application, with their IDs and names.
  • list_tenant_directoriesList the directory-sync connections (e.g. SCIM directories) set up for a tenant by `tenantid`.
  • list_tenant_invitationsList invitations for a tenant by `tenantid`, filtered by `status` (for example pending or accepted).
  • list_tenant_usersList the users who are members of a tenant by `tenantid`, with paging.
  • list_user_organizationsList the tenants (customer organizations) a user belongs to, by `userid`.
  • list_user_rolesList the roles assigned to a user by `userid`.
  • resend_invitationVisible to othersResend a pending tenant invitation by `tenantid` and `invitation_id` (or `invitee`). This sends the invitation email again.
  • search_tenantsList or search tenants (customer organizations) by free text (`search`), with paging. Use to find a tenant's ID.
  • search_usersSearch users by `email` or free text (`search`), with paging. Use to find a user's ID.
  • update_tenantChanges dataUpdate a tenant by `tenantid`: name, display name, domains, external ID or metadata.
  • update_userChanges dataUpdate a user by `userid`: email, phone, name, active status (`is_active`) or metadata. Only the fields you pass change.

Set up in three steps

  1. 1

    Pick the app

    Create a free PipMCP account and choose SSOJet from the app list.

  2. 2

    Paste your key

    Paste the Client ID and Client secret of your SSOJet application, and enter its Client ID again as the Application Client ID. In the SSOJet dashboard open Applications, select your application, open the Advanced tab, enable Client Credentials under grant types and save. Then copy the application's Client ID and Client Secret.

  3. 3

    Add the link to your AI

    You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:

    1. Click your name, then Settings › Connectors › Add custom connector.
    2. Paste your link as the Remote MCP server URL.
    3. Switch it on from the + menu in a chat.

Questions

What can the AI do in SSOJet?

It can search and read users, tenants, tenant members, invitations, roles and directory-sync connections with their synced users and groups. It can create and update users and tenants, add users to tenants, assign roles within a tenant, and invite or re-invite people. It can also delete users if you switch that tool on.

Does the AI see my SSOJet credentials?

No. You paste your SSOJet client ID and secret into PipMCP once. They are encrypted at rest, never shown to the AI and never shown again after you save them. The AI only gets the results of the tools you have switched on.

Can I control what the AI is allowed to do?

Yes. You choose which tools are switched on, so you can start with lookups only. Assigning roles changes what a user can access, invitations send emails and deleting a user is permanent, and these can require your approval before they run. Every tool call is logged.

Does it work with ChatGPT?

Yes. In ChatGPT, open Settings › Apps & Connectors › Advanced, turn on Developer mode and add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.

What does it cost?

PipMCP has a free plan, and you do not need a credit card to start. Paid plans are billed per completed task. You also need your own SSOJet account.

Why do I need to enable Client Credentials?

PipMCP talks to SSOJet as a server, without anyone signing in. SSOJet allows that through the Client Credentials grant, which you turn on for your application under the Advanced tab. The same application's Client ID also tells SSOJet which application's users, tenants and roles the AI works with.

Let your AI work in SSOJet today.

Start free. Your key stays encrypted, and you decide what the AI may do.

Connect SSOJet free

PipMCP is not affiliated with SSOJet. Product names are trademarks of their owners.