Zammad MCP Server

Stateless remote MCP server for Zammad — full ticket operations, an intelligent search layer and OAuth 2.1, running on Node.js or Cloudflare Workers

Local serverstdioTypeScript

What is the Zammad MCP server?

Stateless remote MCP server for Zammad — full ticket operations, an intelligent search layer and OAuth 2.1, running on Node.js or Cloudflare Workers from one codebase. That is what the zammad mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.

The short version

Everything lives in zammad-remote-mcp. The source keeps the runtimes apart, but there is a single version and a single publish.

What it needs from you

Configuration is passed through the environment: PUBLIC_URL, ZAMMAD_URL, ZAMMAD_OAUTH_CLIENT_ID, ZAMMAD_OAUTH_CLIENT_SECRET, OAUTH_STATE_SECRET, ZAMMAD_API_TOKEN, YOUR_ZAMMAD_TOKEN. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

Getting it running

The server ships on npm as zammad-remote-mcp, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.

How it compares

Among the cloud and infrastructure options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. It is maintained by GitHub Actions; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Zammad's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Things to watch

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

How to install the Zammad MCP server

{
  "mcpServers": {
    "remote-1": {
      "command": "npx",
      "args": ["-y", "zammad-remote-mcp"],
      "env": {
        "PUBLIC_URL": "your-value",
        "ZAMMAD_URL": "your-value",
        "ZAMMAD_OAUTH_CLIENT_ID": "your-value",
        "ZAMMAD_OAUTH_CLIENT_SECRET": "your-value",
        "OAUTH_STATE_SECRET": "your-value",
        "ZAMMAD_API_TOKEN": "your-value",
        "YOUR_ZAMMAD_TOKEN": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

VariableDescriptionRequired
PUBLIC_URLEndpoint or connection string the server talks to.Yes
ZAMMAD_URLEndpoint or connection string the server talks to.Yes
ZAMMAD_OAUTH_CLIENT_IDConfiguration value read at startup.Optional
ZAMMAD_OAUTH_CLIENT_SECRETCredential the server authenticates with.Yes
OAUTH_STATE_SECRETCredential the server authenticates with.Yes
ZAMMAD_API_TOKENCredential the server authenticates with.Yes
YOUR_ZAMMAD_TOKENCredential the server authenticates with.Yes

Frequently asked questions

It connects Zammad to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Zammad directly.