Zammad MCP Server — Security
API tokens, least-privilege MCP tool policies, and production security checklist for Zammad MCP.
Security
The MCP server acts as a privileged API client to your Zammad instance. Treat it like any automation integration: scope tokens, deny dangerous tools, and audit usage.
API tokens
- Create a dedicated Zammad user or service account for MCP (not a personal admin account).
- Issue a token under Profile → Token Access with the minimum role needed.
- Store tokens only in environment variables or secret managers — never in git.
- Rotate tokens on schedule or when team members leave.
Official reference: Zammad token access.
Recommended MCP policy for AI agents
MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization
MCP_ALLOWED_CATEGORIES=tickets,users,organizations,groups,system
For read-only exploration:
MCP_DEFAULT_PERMISSION=read_only
MCP_ALLOWED_CATEGORIES=tickets,groups,system
MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization,merge_tickets
MCP_RATE_LIMIT_PER_MINUTE=60
Agents can still create or update tickets if write tools are allowed — review prompts and workflows so humans approve customer-visible articles.
Group and organization scope (0.2.0)
Writes are blocked when the ticket’s group or organization is outside your allow-list:
MCP_ALLOWED_GROUPS=Support
MCP_ALLOWED_ORGANIZATIONS=1,2
Reads respect the same filters — agents cannot bypass scope by guessing ticket IDs.
Rate limiting and audit
MCP_RATE_LIMIT_PER_MINUTE=60
MCP_AUDIT_LOG_PATH=/var/log/zammad-mcp-audit.jsonl
Every tool check is logged as JSON on stderr (Docker/Cloud Run friendly). Optional file append via MCP_AUDIT_LOG_PATH.
Network and transport
| Mode | Guidance |
|---|---|
| stdio (Claude/Cursor) | Process runs locally; token stays on the user machine — suitable for admin workstations |
| HTTP | Docker default (/mcp/). Bind to localhost or place behind TLS + auth |
| SSE | Legacy remote transport; do not expose publicly without a gateway |
Data residency
- Ticket content flows between your Zammad instance and your MCP client host (e.g. Claude Desktop).
- No Open Ticket AI cloud is required for the MCP server itself.
- Review your organization’s policy on sending ticket text to external LLM providers before enabling team-wide use.
Production checklist
- Dedicated Zammad user with least-privilege role
-
MCP_DENIED_TOOLSincludes all delete_* tools for agent configs - HTTPS for
ZAMMAD_URLin production - Tokens stored in secrets manager, not repo
- MCP config excluded from dotfiles backups shared publicly
- Logging reviewed for accidental PII export
- Incident plan: revoke token in Zammad if leaked
Reporting vulnerabilities
Report security issues through the GitHub repository’s security policy: Softoft-Orga/zammad-mcp-server.
