- Home
- Resources
- Integrations
- JupiterOne
Claude JupiterOne connectorWhat Claude can do in your JupiterOne account.
The Claude JupiterOne connector lists 24 tools on its directory sheet. 18 read your asset graph, alerts, rules and integrations, 6 write by building dashboards, editing rules or running an evaluation. Below: what Claude can ask, what it can't delete, and why the docs count more tools.
Verified Trustpilot reviews · AI, automation & growth agency
What changes when Claude can query your graph
JupiterOne maps cloud resources, identities, devices, vulnerabilities and the links between them into a graph you query with J1QL, its own query language. Writing those queries takes practice. With the connector, a security analyst asks "which S3 buckets are public?" in plain words, and Claude answers from the graph, with that analyst's own JupiterOne permissions.
Answer exposure questions fast. execute-j1ql-query runs any J1QL query, with variables, pagination and scope filters.
Triage what's firing. get-active-alerts lists the alerts currently open, list-rules and get-rule-details explain what raised them, and get-rule-evaluation-query-results shows the data behind an evaluation. When a rule needs a fix, update-inline-question-rule changes it and evaluate-rule runs it again on demand.
Check that ingestion is healthy. get-integration-instances and get-integration-jobs tell which integrations ran and which failed, and get-integration-events opens the event log of a job. create-dashboard and create-dashboard-widget turn a recurring question into a dashboard.
What it can't do from the sheet: no deletion at all, of rules, dashboards, entities or integrations. JupiterOne documents delete tools for rules and dashboards, but they aren't on the sheet. Every call also counts against your JupiterOne API rate limits. And nothing runs by itself: Claude queries the graph only when you ask in a conversation. Paging the on-call engineer when an alert fires is automation work, a different job; the Integrations hub covers that side.
The vocabulary in one minute
Five words worth knowing before plugging JupiterOne in.
- Connector
- The link you set up once between Claude and an account you already use, so Claude can work in it while it answers you.
- Tool
- One named action a connector makes available to Claude. It picks the ones it needs while answering; the directory lists them by name.
- Authorization
- The service's own sign-in and consent screen, where you hand Claude the access it will use. Given once per person, and revocable.
- Approval
- The confirmation Claude waits for before finishing something that changes your account, shown in the conversation at that moment.
- MCP
- The common standard behind connectors: it is what lets an assistant such as Claude talk to a service outside it.
Plug JupiterOne into Claude in three steps
- 01
Find JupiterOne in Claude
In Claude's settings, open Customize, then Connectors, and locate JupiterOne. On a Team or Enterprise workspace, an Owner or Primary Owner turns the connector on before members can authenticate one by one.
- 02
Start the connection
Click Connect on its row, then sign in to JupiterOne in the window the service opens itself. If the link breaks later, Disconnect it and connect again from the same row.
- 03
Read the consent screen
Go through the screen before you approve. It belongs to JupiterOne, not Claude, and lists what the connector will be allowed to do before anything is granted. You can revoke it later from JupiterOne too.
The 24 tools, sorted by what they do
JupiterOne gives Claude 24 tools: 18 that read your account, 6 that change something in it.
Two groups: what Claude reads and what it changes. Tool names stay in English, exactly as Claude displays them.
- 18 read
- 6 write
Tools index
- execute-j1ql-query
- get-active-alerts
- get-dashboard-details
- get-dashboards
- get-integration-definitions
- get-integration-events
- get-integration-instances
- get-integration-job
- get-integration-jobs
- get-raw-data-download-url
- get-rule-details
- get-rule-evaluation-details
- get-rule-evaluation-query-results
- list-accounts
- list-entity-types
- list-rule-evaluations
- list-rules
- test-connection
What Claude reads (18)
18 toolsEighteen tools that query the graph, alerts, rules, dashboards and integrations without altering them.
execute-j1ql-query
Runs any J1QL query against your asset graph, with variables, cursor pagination, deleted entities if asked, scope filters and query flags. The entity classes and types it can query are the ones list-entity-types returns.
get-active-alerts
Lists the alerts currently active in the account, with an optional limit between 1 and 1000.
get-dashboard-details
Opens one dashboard in full, with its widgets and its layouts. It only reads the dashboard and leaves its layout exactly as it is.
get-dashboards
Lists all the dashboards in your account. Any one of them can then be opened in full with get-dashboard-details.
get-integration-definitions
Shows which integration types JupiterOne offers, and can include the configuration fields each one expects when you ask for them.
get-integration-events
Returns the events of one integration job, page by page. The job itself can be found first with get-integration-jobs, which filters runs by status.
get-integration-instances
Enumerates the integration instances configured in your account, optionally narrowed to one integration type. The types those instances are built from are listed by get-integration-definitions.
get-integration-job
Fetches the details of one specific integration job from its identifier. It covers one job; the filtered list of jobs comes from get-integration-jobs.
get-integration-jobs
Lists integration jobs, filtered by status, by instance or by definition. The events of any one job can then be read with get-integration-events.
get-raw-data-download-url
Returns a download URL for the raw data of a rule evaluation. The evaluations it applies to are those list-rule-evaluations returns for a rule.
get-rule-details
Shows the full configuration of one rule from its identifier, in full detail. The rule ID can come from list-rules, which returns every rule in the account.
get-rule-evaluation-details
Returns the detailed results of a rule evaluation: the query output, the condition results and the action results. The evaluations themselves are listed, over time, by list-rule-evaluations.
get-rule-evaluation-query-results
Brings back the actual query results produced during one rule evaluation. For the condition and action results around them, get-rule-evaluation-details goes further.
list-accounts
Lists the JupiterOne accounts your login can reach, each with its account ID and display name.
list-entity-types
Discovers all the entity classes and types available in your account, the vocabulary J1QL queries are built on.
list-rule-evaluations
Retrieves the evaluation history of one rule, with an optional time range.
list-rules
Returns every rule defined in the account, with an optional limit on how many come back in one go.
test-connection
Checks that the connection works and returns your account information along with the permissions attached to your user.
What Claude changes (6)
6 toolsSix tools that build dashboards, write or edit rules, or run an evaluation. No source describes a Claude confirmation of their own: the general rule below applies.
create-dashboard
Approval: see the ruleSets up a new, empty dashboard in your JupiterOne account, ready to receive widgets.
create-dashboard-widget
Approval: see the ruleAdds a widget to an existing dashboard.
create-inline-question-rule
Approval: see the ruleWrites a new inline question-based rule, with its queries, operations and actions.
evaluate-rule
Approval: see the ruleTriggers an on-demand evaluation of one specific rule, and the results can then be read with the evaluation tools.
update-dashboard
Approval: see the ruleRearranges the layout of an existing dashboard.
update-inline-question-rule
Approval: see the ruleEdits an existing inline question rule, its queries, operations or actions.
What Claude asks before acting
By default, Claude stops and asks for your go-ahead before each action it carries out on an account for you. The request shows up in the conversation when it matters.
On Team and Enterprise, workspace owners decide whether members can let some actions through without being asked again. They can also cap what a connector does for the whole organization, for instance keeping queries open and closing rule and dashboard changes; nobody overrides that from their own account. Claude works with the rights of the person connected and nothing more. On JupiterOne's side, whatever Claude does is bound by the rights your user already has there.
Which plans include it
Of the 819 sheets in the official directory, none shows availability by plan. Connector by connector, that answer is published nowhere: a real hole in the catalogue, not a gap in our research.
The general rule is public: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner turns the connector on for the organization first. For the current state on your account, check the JupiterOne sheet in the official directory.
Where this connector stops
A connector is not an automation. Claude calls these tools while it answers you; nothing fires when a new alert opens or an integration fails.
The tool list is an observed floor, not a promise: an administrator can open actions that appear on no public sheet. The directory badge isn't a security audit, and Anthropic says on every sheet that it doesn't choose the tools a publisher exposes or guarantee they behave as described. Plug in only publishers you trust. This connector is documented by JupiterOne alone, with no Claude help article.
How many tools does the JupiterOne connector expose?
- Claude directory sheet ↗October 202624 tools, with no deletion and no threat intelligence tool.
- JupiterOne MCP Server documentation ↗undated32 tools spanning queries, threat intelligence, alerts, rules, dashboards, integrations and account discovery.
What this page followsThe docs describe the full service, the sheet what the directory publishes today. The extra tools, including rule and dashboard deletion and threat lookups, aren't on the sheet, so this page doesn't cover them. The list Claude shows on your account after connecting is what counts.
Need help connecting JupiterOne to Claude?
A person reads every message.