# WorkOS MCP server

> Manage WorkOS organizations, users, SSO connections, Directory Sync and AuthKit branding from your assistant.

- Listing: https://mcp.tc/i/workos
- Connect: use the server's own URL `https://mcp.workos.com/mcp` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: WorkOS
- Homepage: <https://workos.com/docs/mcp>
- Repository: <https://github.com/workos/skills/tree/main/mcp>
- Package: npm `@workos/skills`

## About

Connects to the WorkOS API so an assistant can manage your WorkOS workspace. Operations cover organizations, users, SSO connections, Directory Sync, AuthKit branding, webhooks and feature flags. It can also help diagnose SSO sign-in problems for an organization.

This is a hosted Streamable HTTP server at https://mcp.workos.com/mcp. You sign in with OAuth 2.1 through a WorkOS consent screen, and no API keys are pasted. The server acts as your account, inherits your dashboard role, defaults to a sandbox environment, and asks for confirmation before destructive operations.

## What it can do

- Check your identity, role and reachable environments
- List available WorkOS operations with their parameters
- Run read-only queries such as listing organizations or users
- Run write operations such as creating organizations or inviting users
- Provision a WorkOS workspace for a first-time user
- Inspect SSO connections and Directory Sync status
- Adjust AuthKit sign-in branding

## Example prompts

- "Invite bob@example.com to org\_123 as an admin."
- "Help me understand why org\_123 is having trouble signing in with SSO."
- "List every organization with a draft SSO connection."
- "Set up a new organization for Acme Corp in the sandbox environment."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http workos https://mcp.workos.com/mcp
```

2. Start Claude Code, type `/mcp`, pick **workos** and choose **Authenticate**. A browser window opens for the WorkOS sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **WorkOS** and paste this URL:

```url
https://mcp.workos.com/mcp
```

3. Click **Add**, then **Connect**, and sign in when WorkOS asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=WorkOS&connectorUrl=https%3A%2F%2Fmcp.workos.com%2Fmcp>) (opens connector settings)

2. Check that the URL reads `https://mcp.workos.com/mcp` and click **Add**.

3. Click **Connect** and sign in when WorkOS asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.workos.com/mcp` as the server URL and choose **OAuth**. ChatGPT sends you to WorkOS to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=workos&config=eyJ1cmwiOiJodHRwczovL21jcC53b3Jrb3MuY29tL21jcCJ9>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "workos": {
      "url": "https://mcp.workos.com/mcp"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=workos&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.workos.com%2Fmcp%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"workos","type":"http","url":"https://mcp.workos.com/mcp"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "workos": {
      "type": "http",
      "url": "https://mcp.workos.com/mcp"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "workos": {
      "serverUrl": "https://mcp.workos.com/mcp"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add workos --url https://mcp.workos.com/mcp
codex mcp login workos
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.workos]
url = "https://mcp.workos.com/mcp"
```

### Gemini CLI

```bash
gemini mcp add --transport http workos https://mcp.workos.com/mcp
```

Then, inside Gemini CLI, run `/mcp auth workos` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "workos": {
      "type": "http",
      "url": "https://mcp.workos.com/mcp"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.workos.com/mcp`.

## Details

- Server version: 1.0.0
- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/workos (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
