Resources · Claude connector

Claude JupiterOne connectorWhat Claude can do in your JupiterOne account.

The Claude JupiterOne connector lists 24 tools on its directory sheet. 18 read your asset graph, alerts, rules and integrations, 6 write by building dashboards, editing rules or running an evaluation. Below: what Claude can ask, what it can't delete, and why the docs count more tools.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes when Claude can query your graph

JupiterOne maps cloud resources, identities, devices, vulnerabilities and the links between them into a graph you query with J1QL, its own query language. Writing those queries takes practice. With the connector, a security analyst asks "which S3 buckets are public?" in plain words, and Claude answers from the graph, with that analyst's own JupiterOne permissions.

Answer exposure questions fast. execute-j1ql-query runs any J1QL query, with variables, pagination and scope filters.

Triage what's firing. get-active-alerts lists the alerts currently open, list-rules and get-rule-details explain what raised them, and get-rule-evaluation-query-results shows the data behind an evaluation. When a rule needs a fix, update-inline-question-rule changes it and evaluate-rule runs it again on demand.

Check that ingestion is healthy. get-integration-instances and get-integration-jobs tell which integrations ran and which failed, and get-integration-events opens the event log of a job. create-dashboard and create-dashboard-widget turn a recurring question into a dashboard.

What it can't do from the sheet: no deletion at all, of rules, dashboards, entities or integrations. JupiterOne documents delete tools for rules and dashboards, but they aren't on the sheet. Every call also counts against your JupiterOne API rate limits. And nothing runs by itself: Claude queries the graph only when you ask in a conversation. Paging the on-call engineer when an alert fires is automation work, a different job; the Integrations hub covers that side.

Vocabulary

The vocabulary in one minute

Five words worth knowing before plugging JupiterOne in.

Connector
The link you set up once between Claude and an account you already use, so Claude can work in it while it answers you.
Tool
One named action a connector makes available to Claude. It picks the ones it needs while answering; the directory lists them by name.
Authorization
The service's own sign-in and consent screen, where you hand Claude the access it will use. Given once per person, and revocable.
Approval
The confirmation Claude waits for before finishing something that changes your account, shown in the conversation at that moment.
MCP
The common standard behind connectors: it is what lets an assistant such as Claude talk to a service outside it.
Connect

Plug JupiterOne into Claude in three steps

  1. 01

    Find JupiterOne in Claude

    In Claude's settings, open Customize, then Connectors, and locate JupiterOne. On a Team or Enterprise workspace, an Owner or Primary Owner turns the connector on before members can authenticate one by one.

  2. 02

    Start the connection

    Click Connect on its row, then sign in to JupiterOne in the window the service opens itself. If the link breaks later, Disconnect it and connect again from the same row.

  3. 03

    Read the consent screen

    Go through the screen before you approve. It belongs to JupiterOne, not Claude, and lists what the connector will be allowed to do before anything is granted. You can revoke it later from JupiterOne too.

Tools

The 24 tools, sorted by what they do

JupiterOne gives Claude 24 tools: 18 that read your account, 6 that change something in it.

Two groups: what Claude reads and what it changes. Tool names stay in English, exactly as Claude displays them.

  • 18 read
  • 6 write

What Claude reads (18)

18 tools

Eighteen tools that query the graph, alerts, rules, dashboards and integrations without altering them.

execute-j1ql-query

Runs any J1QL query against your asset graph, with variables, cursor pagination, deleted entities if asked, scope filters and query flags. The entity classes and types it can query are the ones list-entity-types returns.

When it helps
an auditor wants every user who can assume a role in a production account.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-active-alerts

Lists the alerts currently active in the account, with an optional limit between 1 and 1000.

When it helps
first thing Monday, the security lead wants a summary of what fired over the weekend, grouped by severity, before the stand-up meeting.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-dashboard-details

Opens one dashboard in full, with its widgets and its layouts. It only reads the dashboard and leaves its layout exactly as it is.

When it helps
a new team member wants to understand what each widget on the compliance dashboard actually measures before presenting it to leadership.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-dashboards

Lists all the dashboards in your account. Any one of them can then be opened in full with get-dashboard-details.

When it helps
you remember a dashboard about cloud spend exposure but not its exact title, and want the list before opening anything.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-integration-definitions

Shows which integration types JupiterOne offers, and can include the configuration fields each one expects when you ask for them.

When it helps
before connecting a new identity provider, you want to know whether a matching integration type exists and which fields it expects.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-integration-events

Returns the events of one integration job, page by page. The job itself can be found first with get-integration-jobs, which filters runs by status.

When it helps
the latest AWS ingestion failed and you want its event log to see where it stopped.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-integration-instances

Enumerates the integration instances configured in your account, optionally narrowed to one integration type. The types those instances are built from are listed by get-integration-definitions.

When it helps
someone asks which cloud accounts are connected to JupiterOne today, and you want the answer without clicking through settings.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-integration-job

Fetches the details of one specific integration job from its identifier. It covers one job; the filtered list of jobs comes from get-integration-jobs.

When it helps
a job flagged as failed in a list needs a closer look before you open a ticket with the team that owns that cloud account.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-integration-jobs

Lists integration jobs, filtered by status, by instance or by definition. The events of any one job can then be read with get-integration-events.

When it helps
you want to know which integrations failed their last run before trusting this morning's figures.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-raw-data-download-url

Returns a download URL for the raw data of a rule evaluation. The evaluations it applies to are those list-rule-evaluations returns for a rule.

When it helps
an incident responder needs the full evaluation output in a spreadsheet to share with an external auditor.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-rule-details

Shows the full configuration of one rule from its identifier, in full detail. The rule ID can come from list-rules, which returns every rule in the account.

When it helps
an alert keeps firing and you want to read the rule behind it before deciding whether it's noise or a real problem.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-rule-evaluation-details

Returns the detailed results of a rule evaluation: the query output, the condition results and the action results. The evaluations themselves are listed, over time, by list-rule-evaluations.

When it helps
you want to understand why a rule raised an alert last night and which condition actually matched.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

get-rule-evaluation-query-results

Brings back the actual query results produced during one rule evaluation. For the condition and action results around them, get-rule-evaluation-details goes further.

When it helps
an alert says twelve assets are exposed and you want their names, not just the number, before assigning remediation to the owners.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

list-accounts

Lists the JupiterOne accounts your login can reach, each with its account ID and display name.

When it helps
a consultant works across several client tenants and needs Claude to aim at the right one first, since each call targets a single account.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

list-entity-types

Discovers all the entity classes and types available in your account, the vocabulary J1QL queries are built on.

When it helps
you're unsure whether your graph models containers as a distinct type and want to check before asking a question about them.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

list-rule-evaluations

Retrieves the evaluation history of one rule, with an optional time range.

When it helps
a rule went quiet for a week and you want to see whether it actually ran during that period or simply found nothing to report.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

list-rules

Returns every rule defined in the account, with an optional limit on how many come back in one go.

When it helps
a newly arrived security engineer wants an overview of every detection already in place before proposing new ones to the team.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

test-connection

Checks that the connection works and returns your account information along with the permissions attached to your user.

When it helps
right after connecting, you want to confirm Claude reaches the right JupiterOne account with the access you expect, before running any real query.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

What Claude changes (6)

6 tools

Six tools that build dashboards, write or edit rules, or run an evaluation. No source describes a Claude confirmation of their own: the general rule below applies.

create-dashboard

Approval: see the rule

Sets up a new, empty dashboard in your JupiterOne account, ready to receive widgets.

What Claude asks for
no source describes a confirmation specific to this tool; the general approval rule applies.
When it helps
a CISO wants a single page that tracks the biggest security risks for the monthly review.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

create-dashboard-widget

Approval: see the rule

Adds a widget to an existing dashboard.

What Claude asks for
no confirmation is documented for this tool; the default rule covers it.
When it helps
you want the count of hosts with critical findings shown permanently instead of asking every week.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

create-inline-question-rule

Approval: see the rule

Writes a new inline question-based rule, with its queries, operations and actions.

What Claude asks for
nothing specific is documented; the approval rule in the next section applies.
When it helps
raising an alert each time a new critical vulnerability appears.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

evaluate-rule

Approval: see the rule

Triggers an on-demand evaluation of one specific rule, and the results can then be read with the evaluation tools.

What Claude asks for
no source describes a confirmation here; the general rule applies.
When it helps
you just fixed a rule's query and want to see what it catches now.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

update-dashboard

Approval: see the rule

Rearranges the layout of an existing dashboard.

What Claude asks for
no source describes a confirmation for this tool; the default approval rule covers it.
When it helps
the most watched widget sits at the bottom and should move to the top before a board presentation.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

update-inline-question-rule

Approval: see the rule

Edits an existing inline question rule, its queries, operations or actions.

What Claude asks for
no confirmation is documented for this tool; the general approval rule applies.
When it helps
a rule floods the team with false positives and its query needs a tighter filter.

Sourcedocs.jupiterone.io · October 1, 2026 ↗

Approvals

What Claude asks before acting

By default, Claude stops and asks for your go-ahead before each action it carries out on an account for you. The request shows up in the conversation when it matters.

On Team and Enterprise, workspace owners decide whether members can let some actions through without being asked again. They can also cap what a connector does for the whole organization, for instance keeping queries open and closing rule and dashboard changes; nobody overrides that from their own account. Claude works with the rights of the person connected and nothing more. On JupiterOne's side, whatever Claude does is bound by the rights your user already has there.

Plans

Which plans include it

Of the 819 sheets in the official directory, none shows availability by plan. Connector by connector, that answer is published nowhere: a real hole in the catalogue, not a gap in our research.

The general rule is public: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner turns the connector on for the organization first. For the current state on your account, check the JupiterOne sheet in the official directory.

Limits

Where this connector stops

A connector is not an automation. Claude calls these tools while it answers you; nothing fires when a new alert opens or an integration fails.

The tool list is an observed floor, not a promise: an administrator can open actions that appear on no public sheet. The directory badge isn't a security audit, and Anthropic says on every sheet that it doesn't choose the tools a publisher exposes or guarantee they behave as described. Plug in only publishers you trust. This connector is documented by JupiterOne alone, with no Claude help article.

Two official sources disagree

How many tools does the JupiterOne connector expose?

What this page followsThe docs describe the full service, the sheet what the directory publishes today. The extra tools, including rule and dashboard deletion and threat lookups, aren't on the sheet, so this page doesn't cover them. The list Claude shows on your account after connecting is what counts.

Need help

Need help connecting JupiterOne to Claude?

A person reads every message.

FAQ

Questions about the Claude JupiterOne connector

01What can Claude do with the JupiterOne connector?
Claude can query your JupiterOne asset graph in plain language by writing and running J1QL, list active alerts, read and explain rules and their evaluations, follow integration jobs and their events, and browse dashboards. Six of the 24 tools on the directory sheet change things: creating dashboards and widgets, creating or updating inline question rules, rearranging a dashboard and running a rule evaluation on demand. Everything runs with your own JupiterOne permissions.
02Can Claude delete rules, dashboards or assets in JupiterOne?
Not with the tools on the directory sheet. None of the 24 deletes anything. JupiterOne documents three delete tools, for rules, dashboards and dashboard widgets, but they don't appear on the sheet, and it states that entities, integrations and other resources can't be deleted through the connector at all. Claude can still create and edit rules and dashboards, and run a rule evaluation on demand. Check the list on your own account after connecting.
03Does Claude ask before changing rules or dashboards?
By default, Claude asks for confirmation before each action it takes on an account for you. No source describes a Claude confirmation specific to the six write tools, so that default rule covers them. JupiterOne adds that its write tools are annotated so clients can prompt for approval. On Team and Enterprise workspaces, owners decide whether members can skip some confirmations, and they can close rule and dashboard changes for everyone.
04Which Claude plans include the JupiterOne connector?
No official source publishes plan availability connector by connector, and none of the 819 directory sheets shows it. The general rule says remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner has to enable the connector before members can connect. The JupiterOne sheet in the official directory is the only place showing the current state for your account.
05Can Claude see our whole JupiterOne environment?
No. Whatever Claude runs is bound by the rights your JupiterOne user already holds, so it sees what your role sees and nothing more. If your login reaches several accounts, each tool still works on one account per call, and list-accounts helps Claude pick the right one. On the Claude side, a workspace owner can also narrow what the connector does for the whole organization, and nobody can lift that from a personal account.
06Why does a JupiterOne query never finish in Claude?
Because some queries take longer than a conversation can wait. JupiterOne says successful queries almost always finish within about 4 minutes, and that past roughly 13 minutes a query will not complete. The tool that collects a long-running result is documented by JupiterOne but isn't on the directory sheet. The practical answer is to ask Claude for a narrower question and try again. Every attempt also counts against your API rate limits, JupiterOne adds.
07Claude or an automation tool for JupiterOne?
They do different jobs, so it depends on the use. Claude suits investigation: asking the graph a question, understanding why an alert fired, adjusting a rule while you talk it through. An automation tool suits reactions that must happen without anyone in a conversation, such as opening a ticket every time a critical alert appears. The connector never starts on its own, so anything event-driven belongs on the automation side.