Zammad MCP Server — Security

API tokens, least-privilege MCP tool policies, and production security checklist for Zammad MCP.

Security

The MCP server acts as a privileged API client to your Zammad instance. Treat it like any automation integration: scope tokens, deny dangerous tools, and audit usage.

API tokens

  1. Create a dedicated Zammad user or service account for MCP (not a personal admin account).
  2. Issue a token under Profile → Token Access with the minimum role needed.
  3. Store tokens only in environment variables or secret managers — never in git.
  4. Rotate tokens on schedule or when team members leave.

Official reference: Zammad token access.

MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization
MCP_ALLOWED_CATEGORIES=tickets,users,organizations,groups,system

For read-only exploration:

MCP_DEFAULT_PERMISSION=read_only
MCP_ALLOWED_CATEGORIES=tickets,groups,system
MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization,merge_tickets
MCP_RATE_LIMIT_PER_MINUTE=60

Agents can still create or update tickets if write tools are allowed — review prompts and workflows so humans approve customer-visible articles.

Group and organization scope (0.2.0)

Writes are blocked when the ticket’s group or organization is outside your allow-list:

MCP_ALLOWED_GROUPS=Support
MCP_ALLOWED_ORGANIZATIONS=1,2

Reads respect the same filters — agents cannot bypass scope by guessing ticket IDs.

Rate limiting and audit

MCP_RATE_LIMIT_PER_MINUTE=60
MCP_AUDIT_LOG_PATH=/var/log/zammad-mcp-audit.jsonl

Every tool check is logged as JSON on stderr (Docker/Cloud Run friendly). Optional file append via MCP_AUDIT_LOG_PATH.

Network and transport

ModeGuidance
stdio (Claude/Cursor)Process runs locally; token stays on the user machine — suitable for admin workstations
HTTPDocker default (/mcp/). Bind to localhost or place behind TLS + auth
SSELegacy remote transport; do not expose publicly without a gateway

Data residency

  • Ticket content flows between your Zammad instance and your MCP client host (e.g. Claude Desktop).
  • No Open Ticket AI cloud is required for the MCP server itself.
  • Review your organization’s policy on sending ticket text to external LLM providers before enabling team-wide use.

Production checklist

  • Dedicated Zammad user with least-privilege role
  • MCP_DENIED_TOOLS includes all delete_* tools for agent configs
  • HTTPS for ZAMMAD_URL in production
  • Tokens stored in secrets manager, not repo
  • MCP config excluded from dotfiles backups shared publicly
  • Logging reviewed for accidental PII export
  • Incident plan: revoke token in Zammad if leaked

Reporting vulnerabilities

Report security issues through the GitHub repository’s security policy: Softoft-Orga/zammad-mcp-server.