Skip to main content
Feedback

CyberArk Conjur MCP connector

Updated 

CyberArk Conjur is CyberArk's open source platform for secrets management and identity access management. The CyberArk Conjur MCP connector allows AI agents to authenticate applications running in AWS, Azure, Google Cloud Platform, and Kubernetes by retrieving short-lived access tokens. It also supports validating authenticator configurations, requesting client certificates for Kubernetes pods, and retrieving Conjur API keys via LDAP and JWT-based authentication methods.

Authentication type

  • Basic Auth - Requires a username and password to be configured for the agent to access the service.

Uses

Use the CyberArk Conjur MCP connector to perform the following actions:

  • Retrieve short-lived access tokens for applications across AWS, Azure, and Google Cloud
  • Rotate role access keys to strengthen credential security without manual intervention
  • Load and update Conjur policies to control resource access and permissions
  • Issue signed certificates from a configured certificate authority for secure connections
  • Create hosts and identity tokens to automate onboarding of new applications
  • Monitor authenticator configuration and server health across Conjur deployments
  • List and audit resources within an organization account for compliance tracking
  • Retrieve user access keys and manage password changes for account security

Example prompts

Use the following example prompts to invoke CyberArk Conjur MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Check if the authentication service is configured correctly in CyberArk Conjur.
  • Get a short-lived access token for our AWS application in CyberArk Conjur.
  • Show me the health status of our CyberArk Conjur server.
  • Rotate the access key for this role in CyberArk Conjur.
  • List all resources in our CyberArk Conjur organization account.
  • Create a new host using the Host Factory in CyberArk Conjur.
  • Get a signed certificate from the certificate authority in CyberArk Conjur.
  • Change the password for this user in CyberArk Conjur.
  • Show me all public keys for this resource in CyberArk Conjur.
  • Load the updated policy document into CyberArk Conjur.

CyberArk Conjur MCP connector tools

The CyberArk Conjur MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
getAuthenticatorsDetails about which authenticators are on the Conjur Server
getAccessTokenViaAzureGets a short-lived access token for applications running in Azure.
getAccessTokenViaGCPGets a short-lived access token for applications running in Google Cloud Platform.
getGCPAuthenticatorStatusDetails whether an authentication service has been configured properly
getAccessTokenViaAWSGet a short-lived access token for applications running in AWS.
getAccessTokenViaJWTGets a short-lived access token for applications using JSON Web Token (JWT) to access the Conjur API.
getAccessTokenViaJWTWithIdGets a short-lived access token for applications using JSON Web Token (JWT) to access the Conjur API.
k8sInjectClientCertFor applications running in Kubernetes; sends Conjur a certificate signing request (CSR) and requests a client certifica...
getAccessTokenViaKubernetesGets a short-lived access token for applications running in Kubernetes.
getAPIKeyViaLDAPGets the Conjur API key of a user given the LDAP username and password via HTTP Basic Authentication.
getAccessTokenViaLDAPGets a short-lived access token for users and hosts using their LDAP identity to access the Conjur API.
getAccessTokenViaOIDCGets a short-lived access token for applications using OpenID Connect (OIDC) to access the Conjur API.
rotateApiKeyRotates a role's API key.
getAPIKeyGets the API key of a user given the username and password via HTTP Basic Authentication.
changePasswordChanges a user’s password.
getAccessTokenGets a short-lived access token, which is required in the header of most subsequent API requests.
signGets a signed certificate from the configured Certificate Authority service.
healthHealth info about conjur
createHostCreates a Host using the Host Factory.
createTokenCreates one or more host identity tokens.
revokeTokenRevokes a token, immediately disabling it.
infoBasic information about the Conjur Enterprise server
updatePolicyModifies an existing Conjur policy.
loadPolicyAdds data to the existing Conjur policy.
replacePolicyLoads or replaces a Conjur policy document.
showPublicKeysShows all public keys for a resource.
remoteHealthHealth info about a given Conjur Enterprise server
showResourcesForAllAccountsLists resources within an organization account.
showResourcesForAccountLists resources within an organization account.
showResourcesForKindLists resources of the same kind within an organization account.
showResourceShows a description of a single resource.
removeMemberFromRoleDeletes an existing role membership
showRoleGet role information
addMemberToRoleUpdate or modify an existing role membership
getSecretsFetch multiple secrets
getSecretFetches the value of a secret from the specified Secret.
whoAmIProvides information about the client making an API request.
enableAuthenticatorEnables or disables authenticator defined without service_id.
enableAuthenticatorInstanceEnables or disables authenticator service instances.
getServiceAuthenticatorStatusDetails whether an authentication service has been configured properly
On this Page