Skip to content
CyberArk logo

CyberArk MCP server

Manage users, groups, and access controls in CyberArk Privileged Access Management

CyberArk is not a separate install. One Activepieces MCP server exposes it alongside 760+ other apps, behind a single URL.

Tools
17
Works with
Any MCP client
Auth
Custom auth
License
MIT, open source
Updated
August 2026

About the CyberArk MCP server

Connect CyberArk once in Activepieces and every action it ships becomes a tool your assistant can call, behind the same server URL as the rest of your apps. Your agent reaches CyberArk and 760+ other apps over a single connection, on our cloud or a self-hosted install.

Tools

CyberArk tools your AI can run

Once connected, your assistant can call any of these CyberArk actions by asking in plain language.

  • Create User

    Creates a new user in the CyberArk Vault

    39 fields

  • Update User

    Updates an existing Vault user (except Master and Batch built-in users)

    45 fields

  • Delete User

    Deletes a specific user in the Vault (requires Add/Update Users authorization)

    2 fields

  • Activate User

    Activates an existing user who was suspended after entering incorrect credentials multiple times

    1 field

  • Enable User

    Enables a specific user in the Vault

    1 field

  • Disable User

    Disables a specific user in the Vault

    1 field

  • Find User

    Returns a list of existing users in the Vault based on filter criteria (requires Audit users permissions)

    8 fields

  • Add Member to Group

    Adds a user as a member to an existing Vault group (requires Add/Update users permissions)

    4 fields

  • Remove Member from Group

    Removes a specific user from a user group in the Vault

    2 fields

  • Get Password Value

    Retrieves the password or SSH key of an existing account identified by its Account ID

    8 fields

  • Retrieve Private SSH Key

    Retrieves a private SSH key file from an existing account identified by its Account ID

    8 fields

  • Change Credentials in the Vault

    Sets account credentials and changes them in the Vault. This will not affect credentials on the target device.

    2 fields

  • Verify Credentials in Bulk

    Marks multiple accounts for verification by the CPM

    1 field

  • Change Credentials Immediately in Bulk

    Marks multiple accounts for an immediate credentials change by the CPM to a new random value

    2 fields

  • Set Next Password in Bulk

    Sets multiple accounts' credentials to use for the next CPM change

    1 field

  • Change Credentials in the Vault in Bulk

    Sets credentials for multiple accounts and changes them in the Vault. This does not affect credentials on the target device.

    1 field

  • Reconcile Credentials in Bulk

    Marks multiple accounts for automatic reconciliation by the CPM

    1 field

Give your assistant CyberArk

Connect CyberArk once and every tool above is callable from Claude, Cursor or any MCP client, behind the same server URL as 760+ other apps. Free to start.

CyberArk MCP, answered.

No. That is the point of it. One Activepieces server exposes CyberArk alongside every other piece you connect, so your client keeps a single connection.

Yes. Activepieces is open source and free to start, and the MCP server is included on every plan, from the free cloud tier to any self-hosted deployment.

Connect CyberArk in Activepieces, enable the server under Settings → MCP Server, then paste your server URL into your client config. It authenticates over OAuth on first use.

It can call 17 tools, including Create User, Update User, Delete User, and chain them with steps in other apps inside the same run.

Connections use OAuth2 with limited scopes and are stored under 256-bit encryption, with no API to read them back, so an agent gets scoped access rather than your keys.