ZendeskSAFE
A Model Context Protocol server for Zendesk
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/Apache-2.0)
A Model Context Protocol server for Zendesk.
This server provides a comprehensive integration with Zendesk. It offers:
- Tools for retrieving and managing Zendesk tickets and comments
- Specialized prompts for ticket analysis and response drafting
- Full access to the Zendesk Help Center articles as knowledge base
Setup
- build:
uv venv && uv pip install -e .oruv buildin short. - configure authentication: see Authentication below.
- configure in Claude desktop:
{
"mcpServers": {
"zendesk": {
"command": "uv",
"args": [
"--directory",
"/path/to/zendesk-mcp-server",
"run",
"zendesk"
]
}
}
}Authentication
This server authenticates with OAuth. Each operator authorizes with their own Zendesk login, so API calls carry their identity and Zendesk applies exactly the permissions it applies in the UI — their role, their group restrictions, their ticket access. Comments they post are authored by them.
API token authentication still works but is deprecated. See Migrating from an API token.
1. Register a public OAuth client
In Admin Center, go to Apps and integrations > APIs > OAuth clients and create a client:
Setting Allowed scopes is optional but recommend
a4baeab35602OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add zendesk-mcp-server -- uvx zendesk-mcp-server
{
"mcpServers": {
"zendesk-mcp-server": {
"command": "uvx",
"args": [
"zendesk-mcp-server"
]
}
}
}Exposed tools (7)
4 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_ticket | write | Create a new Zendesk ticket |
create_ticket_comment | write | Create a new comment on an existing Zendesk ticket |
get_ticket | read | Retrieve a Zendesk ticket by its ID |
get_ticket_attachment | read | Fetch a Zendesk ticket attachment by its content_url and return the file as base64-encoded data. Use the attachment URLs returned by get_ticket_comments. |
get_ticket_comments | read | Retrieve all comments for a Zendesk ticket by its ID |
get_tickets | read | Fetch the latest tickets with pagination support |
update_ticket | write | Update fields on an existing Zendesk ticket (e.g., status, priority, assignee_id) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
redirect_uri=f"http://127.0.0.1:{port}/callback",f"http://127.0.0.1:{port}/callback?error=access_denied", timeout=5assert base64.b64decode(result["data"]) == body
- Full access to the Zendesk Help Center articles as knowledge base
account-level and unscoped. Whoever holds it gets the full access of the user it
Gates applied: no_behavioural_pass.
a4baeab35602full audit observations/trust-audit/mcp-server/reminia__zendesk.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a4baeab35602 | SAFE | B | 89 | first audit |
Questions
What is the Zendesk MCP server?
A Model Context Protocol server for Zendesk
What tools does Zendesk expose?
7 in total: 4 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Zendesk safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Zendesk need?
No credential environment variables were found in its source, so it appears to need none.
How does Zendesk run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as zendesk-mcp-server.
How current is this page?
The grade is for one exact copy of the source (a4baeab35602), read on 2026-10-07. The repository is watched and re-audited when it changes.