Zammad MCP Server — Agent Workflows
Practical MCP workflows for Zammad 0.2.0 — summarize tickets, tags, attachments, links, and remote HTTP deployment.
Agent Workflows
Version 0.2.0 adds composite tools and helpdesk workflows that reduce tool-chaining in Claude Desktop and Cursor. This page shows copy-paste prompts and the MCP tools behind them.
One-call ticket summary
Instead of calling get_ticket, get_ticket_articles, and tag tools separately, use summarize_ticket:
Summarize Zammad ticket 12345 with
summarize_ticket. Show the plain-text thread, tags, and the last customer message.
The response includes:
| Field | Use for agents |
|---|---|
thread_plain | Chronological conversation without HTML noise |
tags | Current ticket tags |
last_customer_message | Fast context for drafting a reply |
last_agent_message | What the team already said |
article_count | Thread length / escalation signal |
Articles also expose body_plain when MCP_STRIP_HTML=1 (default) on get_ticket and get_ticket_articles.
Search → tag → reply (≤3 tool calls)
Typical support triage in three MCP steps:
-
Search —
search_ticketswith a Zammad query:state.name:open AND group.name:Support AND customer.email:jane@example.com -
Tag —
add_ticket_tagon the chosen ticket ID (for exampleurgent-review). -
Reply —
create_articlewith optional attachment (see below).
Example prompt for Cursor or Claude:
Search open Support tickets for
customer.email:jane@example.com. On the newest match, add tagneeds-callbackand draft an internal note that we will call back today.
Recommended env for this workflow (writes allowed, deletes denied):
MCP_ALLOWED_CATEGORIES=tickets,system
MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization,merge_tickets
MCP_ALLOWED_GROUPS=Support
MCP_ALLOWED_GROUPS blocks writes to tickets outside the listed groups.
Attachments
Read an attachment
- Call
get_ticket_articles(orsummarize_ticket) and read each article’sattachmentslist (id,filename,size). - Call
get_article_attachment(ticket_id, article_id, attachment_id, as_text=True)for plain text files.
For binary files the tool returns base64 in data.
Send an attachment with a reply
Pass attachments when calling create_article or create_ticket:
{
"filename": "screenshot.png",
"data": "<base64>",
"mime_type": "image/png"
}
The server maps mime_type to Zammad’s mime-type JSON field automatically.
Example prompt:
Reply on ticket 12345 with a public note “Please see the attached log.” Attach the file
error.logas text/plain.
Link and merge tickets
| Tool | Permission | When to use |
|---|---|---|
link_tickets | WRITE | Relate duplicates (normal, parent, child) |
merge_tickets | ADMIN | Combine two tickets into one customer-visible ID |
Example:
Link ticket 100 as child of ticket 99, then summarize ticket 99.
Deny merge in agent configs unless a human explicitly approves:
MCP_DENIED_TOOLS=delete_ticket,delete_user,delete_organization,merge_tickets
Built-in MCP prompts (0.2.0)
Clients that support MCP prompts can invoke:
| Prompt | Parameters (examples) | Purpose |
|---|---|---|
analyze_ticket | ticket_id, locale | Structured history + SLA hints |
draft_response | ticket_id, locale | Customer or internal reply draft |
triage_queue | group | Prioritize open tickets |
escalation_summary | group | Overdue / pending-close briefing |
Legacy prompts from 0.1.x remain available: ticket_summary_prompt, customer_communication_prompt, escalation_analysis_prompt.
Remote HTTP MCP (Docker default)
For LibreChat, remote Cursor setups, or Zammad Commander, run Streamable HTTP:
zammad-mcp-server --transport http --host 0.0.0.0 --port 8000
| Setting | Value |
|---|---|
| Path | /mcp/ (override with --path) |
| Env alternative | MCP_TRANSPORT=http, MCP_SERVER_PORT=8000 |
| Docker image | Same command is the container default |
| Health | TCP on port 8000 — no /health route |
Legacy SSE clients:
zammad-mcp-server --transport sse --host 0.0.0.0 --port 8000
Path defaults to /sse/. Use only on trusted networks or behind TLS.
Read-only demo preset
Safe configuration for first demos or read-only exploration:
MCP_DEFAULT_PERMISSION=read_only
MCP_ALLOWED_CATEGORIES=tickets,groups,system
MCP_DENIED_TOOLS=create_ticket,update_ticket,delete_ticket,create_article,merge_tickets
MCP_RATE_LIMIT_PER_MINUTE=60
Verify with: “Call get_allowed_tools and list what I can do.”
Related
- Tools Reference — full tool list
- Configuration — all environment variables
- Security — production checklist
- Deployment — Docker and HTTP details
