CyberArk Conjur MCP connector
CyberArk Conjur is CyberArk's open source platform for secrets management and identity access management. The CyberArk Conjur MCP connector allows AI agents to authenticate applications running in AWS, Azure, Google Cloud Platform, and Kubernetes by retrieving short-lived access tokens. It also supports validating authenticator configurations, requesting client certificates for Kubernetes pods, and retrieving Conjur API keys via LDAP and JWT-based authentication methods.
Authentication type
- Basic Auth - Requires a username and password to be configured for the agent to access the service.
Uses
Use the CyberArk Conjur MCP connector to perform the following actions:
- Retrieve short-lived access tokens for applications across AWS, Azure, and Google Cloud
- Rotate role access keys to strengthen credential security without manual intervention
- Load and update Conjur policies to control resource access and permissions
- Issue signed certificates from a configured certificate authority for secure connections
- Create hosts and identity tokens to automate onboarding of new applications
- Monitor authenticator configuration and server health across Conjur deployments
- List and audit resources within an organization account for compliance tracking
- Retrieve user access keys and manage password changes for account security
Example prompts
Use the following example prompts to invoke CyberArk Conjur MCP connector tools from your AI assistant or Boomi Connect workflow:
Check if the authentication service is configured correctly in CyberArk Conjur.Get a short-lived access token for our AWS application in CyberArk Conjur.Show me the health status of our CyberArk Conjur server.Rotate the access key for this role in CyberArk Conjur.List all resources in our CyberArk Conjur organization account.Create a new host using the Host Factory in CyberArk Conjur.Get a signed certificate from the certificate authority in CyberArk Conjur.Change the password for this user in CyberArk Conjur.Show me all public keys for this resource in CyberArk Conjur.Load the updated policy document into CyberArk Conjur.
CyberArk Conjur MCP connector tools
The CyberArk Conjur MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| getAuthenticators | Details about which authenticators are on the Conjur Server |
| getAccessTokenViaAzure | Gets a short-lived access token for applications running in Azure. |
| getAccessTokenViaGCP | Gets a short-lived access token for applications running in Google Cloud Platform. |
| getGCPAuthenticatorStatus | Details whether an authentication service has been configured properly |
| getAccessTokenViaAWS | Get a short-lived access token for applications running in AWS. |
| getAccessTokenViaJWT | Gets a short-lived access token for applications using JSON Web Token (JWT) to access the Conjur API. |
| getAccessTokenViaJWTWithId | Gets a short-lived access token for applications using JSON Web Token (JWT) to access the Conjur API. |
| k8sInjectClientCert | For applications running in Kubernetes; sends Conjur a certificate signing request (CSR) and requests a client certifica... |
| getAccessTokenViaKubernetes | Gets a short-lived access token for applications running in Kubernetes. |
| getAPIKeyViaLDAP | Gets the Conjur API key of a user given the LDAP username and password via HTTP Basic Authentication. |
| getAccessTokenViaLDAP | Gets a short-lived access token for users and hosts using their LDAP identity to access the Conjur API. |
| getAccessTokenViaOIDC | Gets a short-lived access token for applications using OpenID Connect (OIDC) to access the Conjur API. |
| rotateApiKey | Rotates a role's API key. |
| getAPIKey | Gets the API key of a user given the username and password via HTTP Basic Authentication. |
| changePassword | Changes a user’s password. |
| getAccessToken | Gets a short-lived access token, which is required in the header of most subsequent API requests. |
| sign | Gets a signed certificate from the configured Certificate Authority service. |
| health | Health info about conjur |
| createHost | Creates a Host using the Host Factory. |
| createToken | Creates one or more host identity tokens. |
| revokeToken | Revokes a token, immediately disabling it. |
| info | Basic information about the Conjur Enterprise server |
| updatePolicy | Modifies an existing Conjur policy. |
| loadPolicy | Adds data to the existing Conjur policy. |
| replacePolicy | Loads or replaces a Conjur policy document. |
| showPublicKeys | Shows all public keys for a resource. |
| remoteHealth | Health info about a given Conjur Enterprise server |
| showResourcesForAllAccounts | Lists resources within an organization account. |
| showResourcesForAccount | Lists resources within an organization account. |
| showResourcesForKind | Lists resources of the same kind within an organization account. |
| showResource | Shows a description of a single resource. |
| removeMemberFromRole | Deletes an existing role membership |
| showRole | Get role information |
| addMemberToRole | Update or modify an existing role membership |
| getSecrets | Fetch multiple secrets |
| getSecret | Fetches the value of a secret from the specified Secret. |
| whoAmI | Provides information about the client making an API request. |
| enableAuthenticator | Enables or disables authenticator defined without service_id. |
| enableAuthenticatorInstance | Enables or disables authenticator service instances. |
| getServiceAuthenticatorStatus | Details whether an authentication service has been configured properly |